{"id":2638,"date":"2022-03-16T13:54:57","date_gmt":"2022-03-16T19:54:57","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2638"},"modified":"2022-04-11T11:32:58","modified_gmt":"2022-04-11T17:32:58","slug":"russia-issues-its-own-tls-certificate-to-bypass-sanctions%ef%bf%bc","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/16\/russia-issues-its-own-tls-certificate-to-bypass-sanctions%ef%bf%bc\/","title":{"rendered":"Russia issues its own TLS certificate to bypass sanctions"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2022\/03\/04\/tls-header-image.jpg\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In response to Russia\u2019s invasion of Ukraine, many Western countries have imposed sanctions prohibiting companies from conducting business in Russia, including public third-party certificate authorities (CA), which issue Digital Certificates and manage the public keys and credentials for data encryption for the end user. One of such Digital Certificates is the Transport Layer Security (TLS), which plays an integral role in validating website domains to ensure security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the sanction preventing certificate renewal for Russian websites, websites with expired TLS certificates are blocked by browsers. In an attempt to solve the website access problems, Russia has created its own TLS certificate authority.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How TLS certificates work?<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1.jpg\" alt=\"\" class=\"wp-image-2639 lazyload\" width=\"655\" height=\"244\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1.jpg 936w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1-300x112.jpg 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1-768x287.jpg 768w\" data-sizes=\"(max-width: 655px) 100vw, 655px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 655px; --smush-placeholder-aspect-ratio: 655\/244;\" \/><figcaption>How TLS works (Source: DigiCert)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">TLS, also known as SSL or digital certificates, is the foundation of secure networks and the successor technology of the commonly known Secure Sockets Layer (SSL). TLS is a cryptographic protocol that provides end-to-end security of data sent over the Internet. It is most known for its use in securing HTTPS web browsing and is visible as the padlock symbol in the address bar. Aside from web browsing, it is also used in applications such as email, messaging, and voice over IP.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-src=\"https:\/\/cf-assets.www.cloudflare.com\/slt3lc6tev37\/5aYOr5erfyNBq20X5djTco\/3c859532c91f25d961b2884bf521c1eb\/tls-ssl-handshake.png\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><figcaption>TLS Handshake (Source: CloudFlare)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A TLS handshake is the process that initiates a communication session with TLS encryption. During a TLS handshake, the client and the server exchange messages to acknowledge each other, verify each other, establish the encryption algorithms they will use, and agree on session keys. This can be summarized as the following steps:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Specify which version of TLS is in use<\/li><li>Decide on which cipher suites to use, which is a set of encryption algorithms such as &nbsp;RSA key exchange algorithm<\/li><li>Authenticate the identity of the server via the server\u2019s public key and the TLS certificate authority\u2019s digital signature<\/li><li>Generate session keys to use symmetric encryption<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">TLS typically relies on trusted third-party CA to establish the certificates, the top 3 of which are IdenTrust, DigiCert and Sectigo. With some of these companies withdrawing businesses from Russia and sanctions causing these companies unable to receive payments from Russia, the country is now facing website access issues as these websites are now unable to renew their certificates, and hence, being blocked by web browsers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Russia&#8217;s Domestic TLS<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"936\" height=\"326\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-2.jpg\" alt=\"\" class=\"wp-image-2640 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-2.jpg 936w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-2-300x104.jpg 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-2-768x267.jpg 768w\" data-sizes=\"(max-width: 936px) 100vw, 936px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 936px; --smush-placeholder-aspect-ratio: 936\/326;\" \/><figcaption><strong>Announcing the availability of domestic certificates<\/strong> (<strong>Gosuslugi)<\/strong><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The Russian government envisions a solution of generating TLS certificates on their own to websites in the country: \u201cIt will replace the foreign security certificate if it is revoked or expires. The Ministry of Digital Development will provide a free domestic analogue. The service is provided to legal entities \u2013 site owners upon request within 5 working days,\u201d explains the Russian public services portal, Gosuslugi (translated).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Risks and Limitations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">However, this plan comes with many limitations. The TLS certificates require the validation from web browsers, meaning that browsers are free to reject websites they deem not trust-worthy. Additionally, the process of adding certificate issuers to a \u201cwhitelist\u201d takes several months at the minimum, leaving Russian domestic TLS being rejected by major Western browsers at the moment. The only web browsers that are accepting Russia\u2019s domestic TLS are Yandex and Atom browser, both of which are based in Russia.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This also creates a significant privacy threat to the Russian residents \u2013 Mike Parkin, researcher and senior technical engineer at Vulcan Cyber, tells CSO News \u201cWhile it\u2019s unlikely that the major browsers will ever accept the new Russian CA, it may be a problem for those users in Russia. They will have to rely on their CA, which is sanctioned by a government that is not well known for respecting user privacy or taking a strong stand against cybercriminals.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Bottom Line<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This action of Russian government prompted many to wonder if this is a step towards the Russian \u201csovereign internet\u201d, where the nation completely disconnect from global Internet. &nbsp;\u201cThis would happen under a 2019 Law on Sovereign Internet. According to Russia\u2019s legislation, disconnecting Russian internet infrastructure from the global internet would be a defensive move, although this leaves a wide room for interpretation,\u201d according to a Flashpoint post.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sources:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.globalsign.com\/en\/ssl-information-center\/what-are-certification-authorities-trust-hierarchies\">https:\/\/www.globalsign.com\/en\/ssl-information-center\/what-are-certification-authorities-trust-hierarchies<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.digicert.com\/tls-ssl\/tls-ssl-certificates\">https:\/\/www.digicert.com\/tls-ssl\/tls-ssl-certificates<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.internetsociety.org\/deploy360\/tls\/basics\/\">https:\/\/www.internetsociety.org\/deploy360\/tls\/basics\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cloudflare.com\/en-ca\/learning\/ssl\/what-happens-in-a-tls-handshake\/\">https:\/\/www.cloudflare.com\/en-ca\/learning\/ssl\/what-happens-in-a-tls-handshake\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.csoonline.com\/article\/3653315\/traffic-interception-and-mitm-attacks-among-security-risks-of-russian-tls-certs.html\">https:\/\/www.csoonline.com\/article\/3653315\/traffic-interception-and-mitm-attacks-among-security-risks-of-russian-tls-certs.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.flashpoint-intel.com\/blog\/ukraine-russia-war\/russian-runet-sovereign-internet\/\">https:\/\/www.flashpoint-intel.com\/blog\/ukraine-russia-war\/russian-runet-sovereign-internet\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In response to Russia\u2019s invasion of Ukraine, many Western countries have imposed sanctions prohibiting companies from conducting business in Russia, including public third-party certificate authorities (CA), which issue Digital Certificates and manage the public keys and credentials for data encryption for the end user. One of such Digital Certificates is the Transport Layer Security (TLS), &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/16\/russia-issues-its-own-tls-certificate-to-bypass-sanctions%ef%bf%bc\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Russia issues its own TLS certificate to bypass sanctions&#8221;<\/span><\/a><\/p>\n","protected":false},"author":346,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[16,13,39],"class_list":["post-2638","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","tag-cpsc329","tag-cybersecurity","tag-russia","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Melissa Hoang","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/melissa-hoang\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/346"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2638"}],"version-history":[{"count":5,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2638\/revisions"}],"predecessor-version":[{"id":3063,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2638\/revisions\/3063"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}