Let's Downgrade Let's Encrypt
Tianxiang Dai, Haya Schulmann, Michael Waidner
Abstract
Following the recent off-path attacks against PKI, Let's Encrypt deployed in 2020 domain validation from multiple vantage points to ensure security even against the stronger on-path MitM adversaries. The idea behind such distributed domain validation is that even if the adversary can hijack traffic of some vantage points, it will not be able to intercept traffic of all the vantage points to all the nameservers in a domain. In this work we show that two central design issues of the distributed domain validation of Let's Encrypt make it vulnerable to downgrade attacks: (1) the vantage points are selected from a small fixed set of vantage points, and (2) the way the vantage points select the nameservers in target domains can be manipulated by a remote adversary. We develop off-path methodologies, based on these observations, to launch downgrade attacks against Let's Encrypt. The downgrade attacks reduce the validation with 'multiple vantage points to multiple nameservers', to validation with 'multiple vantage points to a single attacker-selected nameserver'. Through experimental evaluations with Let's Encrypt and the 1M-Let's Encrypt-certified domains, we find that our off-path attacker can successfully launch downgrade attacks against more than 24.53% of the domains, rendering Let's Encrypt to use a single nameserver for validation with them. We then develop an automated off-path attack against the 'single-server'-domain validation for these 24.53% domains, to obtain fraudulent certificates for more than 107K domains, which constitute 10% of the 1M domains in our dataset. We also evaluate our attacks against other major CAs and compare the security and efforts needed to launch the attacks, to those needed to launch the attacks against Let's Encrypt. We provide recommendations for mitigations against our attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 82b42847-caf4-4118-804f-ff945c09228cCited by top-tier papers6
- Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersFenglu Zhang, Baojun Liu, Eihal Alowaisheq, Jianjun Chen et al.CCS 2023 · 3 citations
- NOPE: Strengthening domain authentication with succinct proofsZachary DeStefano, Jeff J. Ma, Joseph Bonneau, Michael WalfishSOSP 2024 · 2 citations
- Downgrading DNSSEC: How to Exploit Crypto Agility for Hijacking Signed ZonesElias Heftrig, Haya Schulmann, Michael WaidnerUSENIX Security 2023
- How Effective is Multiple-Vantage-Point Domain Control Validation?Grace H. Cimaszewski, Henry Birge-Lee, Liang Wang, Jennifer Rexford et al.USENIX Security 2023
- Certificate Transparency Revisited: The Public Inspections on Third-party MonitorsAozhuo Sun, Jingqiang Lin, Wei Wang, Zeyan Liu et al.NDSS 2024
Related papers
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker et al.USENIX Security 2021 · 23 citations
- ValidaTor: Domain Validation over TorJens Frieß, Haya Schulmann, Michael WaidnerNSDI 2025
- Stalloris: RPKI Downgrade AttackTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.USENIX Security 2022
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann et al.CCS 2018 · 71 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
