Monday, July 31, 2006

Garden Certificate - Microsoft MVP Site


In "Garden Certificate Basics", I provided background information about Website Certificates, including an example of a highly questionable website using a false certificate. This was brought about by a question a visitor to this site raised when presented with a Certificate for mvp.support.microsoft.com, which is linked in my first blog entry, "About Me".

In order to demonstrate how to examine a safe certificate, I deleted the certificate from my computer for mvp.support.microsoft.com. After closing the browser and reopening the link for this blog site, I was immediately presented with the certificate notice below. This gave me the option to accept the certificate permanently, accept the certificate just for the session, or, finally, to not only not allow the certificate but also not connect to the site.
Note that the pre-selected option is to temporarilly accept the certificate for the session:


I had one additional choice. That was to Examine the Certificate. That is the option I selected which opened the Certificate Viewer. Note the information presented: "Could not verify this certificate because the issuer is unknown." That does not mean that the site is not safe. The statement merely reflects that mvp.support.microsoft.com (in this instance) is not a recognized authority. Additionally note, however, the Common Name (CN) on the Certificate: mvp.support.microsoft.com.


Observe on the detail screen that the Certificate Hierarchy is indicated as mvp.support.microsoft.com. That matches the site URL linked in the previously mentioned blog entry, "About Me".

With those details; that is, the Common Name (from the General tab) and the Certificate Heirarchy both matching the URL for the MVP site, you know that it is safe to close the Certificate Viewer, and accept the certificate.


Saturday, July 29, 2006

Garden Certificate Basics

I received an email last week that someone had visited Security Garden and was presented with the following message when visiting with Firefox:

"Unable to verify the identity of mvp.support.Microsoft.com as a trusted site"

As it was relayed to me, the certificate warning then provided the individual the choice of accepting the site or not.

This warning justifiably raised questions in the person's mind. What is a certificate? Is it some type of award? Does the message mean the Microsoft MVP link isn't safe? Does it mean that this site isn't safe? I assure you that the information I provide here in the Security Garden is safe, as is the MVP site. I would not intentionally post links to inappropriate or unsafe sites.

It is time to talk about digital certificates. For a technical explanation of digital certificates, see this Microsoft Technet article by Roger Grimes, entitled "Authenticode". For a hands-on, what are they, what to do, explanation, read on.


According to the definition from WhatIs.com,
A digital certificate is an electronic "credit card" that establishes your credentials when doing business or other transactions on the Web. It is issued by a certification authority (CA). It contains your name, a serial number, expiration dates, a copy of the certificate holder's public key (used for encrypting messages and digital signatures), and the digital signature of the certificate-issuing authority so that a recipient can verify that the certificate is real. Some digital certificates conform to a standard, X.509. Digital certificates can be kept in registries so that authenticating users can look up other users' public keys.
Simply stated, a public key certificate uses a digital signature to connect the public key with an identify. In the case the reader of this site encountered, it was information presented to verify that the key belongs to Microsoft. It is the digital equivalent of an ID card, providing the name of an individual or other entity certifying that the public key, which is included in the certificate, belongs to that individual or entity.

With all that information, what do you do when presented with a certificate? Here's an example of a site with a faked certificate, discussed at Security and Secure IT:

As soon as the site in question was placed in the address bar, the Domain Name Mismatch error popped up indicating that the site was presenting a security certificate belonging to www.microsoft.com. Since I had no doubt that the certificate did not belong to that site, I clicked Cancel. From Subratam's report, I already know that the site in question has been reported as attempting to clone a Microsoft site.

If you elect not to be bothered with those details and want to let Firefox select a certificate for you, click on Tools > Options > Advanced. Under Certificates, select the option to have Firefox select a certificate automatically.

Garden Phone May "Call Forward"!

I expressed my original concerns with regard to Microsoft's "Windows Genuine Advantage" (WGA) software tools last month in "Garden Phone?". This morning I was reading a post in the Microsoft WGA Forum, entitled, "Is MS making my PC phone home?". A link within that thread led to discovering the following statement located in the "Microsoft Genuine Advantage Privacy Statement":

"How is this data used?

We use the information to

  • Help prevent improperly licensed use of the software
  • Improve our software and services
  • Develop aggregate statistics.
We may also share aggregate data with others, such as hardware and software vendors and volume licensees to help protect their license keys." {Bold added}
To be certain that I was not misunderstanding the definition of "aggregate", I checked the Merriam-Webster Online Dictionary:
"Main Entry: 1ag·gre·gate
Pronunciation: 'a-gri-g&t
Function: adjective
Etymology: Middle English aggregat, from Latin aggregatus, past participle of aggregare to add to, from ad- + greg-, grex flock
: formed by the collection of units or particles into a body, mass, or amount"
Aggregate is not defined as a summary but as being formed by the collection of units. In the context used by Microsoft in the privacy statement quoted above, I am certainly led to believe that such an aggregate will include all information collected by Microsoft with the WGA tools.

You might ask what information Microsoft collects. Again from the "Microsoft Genuine Advantage Privacy Statement":

"The tools collect such information as:

  • Computer make and model
  • Version information for the operating system and software using Genuine Advantage
  • Region and language setting
  • A unique number assigned to your computer by the tools (Globally Unique Identifier or GUID)
  • Product ID and Product Key
  • BIOS name, revision number, and revision date
  • Hard drive serial number
In addition to the configuration information above, status information such as the following is also transferred:
  • Whether the installation was successful
  • The result of the validation check

    . . . To help protect your privacy, only a non-unique portion of your IP address is used and retained with the information collected above."

Microsoft legal beagles have certainly left their footprint on the privacy statement. It is extremely general, with absolutely no limitation or indication of which hardware and/or software vendors this collection could be shared with. Will the data be sold to the highest bidder? Will the recipient vendors maintain the data secure or publish it for their own marketing purposes? Imaginary headline reading: "XYZ Software Company holds market share of Microsoft customers with their XYZ Software! Statistics follow."

Marketing departments could further benefit from this information, targeting their software based on region, narrowed by IP Address. After all, even though Microsoft retains only "a non-unique portion of your IP address", coupled with the region and language, that would be sufficient for vendors to target advertisements to areas not using their product based on the aggregate data collected by Microsoft.

Microsoft is not the world police force and, in my opinion, does not belong providing any data to other vendors. Message to Microsoft: Stick to protecting Microsoft license keys, not those of other vendors!