Softethervpn: Use https to download binary files.

Created on 2 Nov 2017  路  34Comments  路  Source: SoftEtherVPN/SoftEtherVPN

We can download binaries on the page http://www.softether-download.com/en.aspx.
This page does not have HTTPS version...
Is it possible to fix that? Or alternatively publish SHA-256 hashes on page https://www.softether.org/5-download (which is secured by COMODO certificate).

feature security vulnerability

Most helpful comment

@ann0see The link you posted is extremely important and the critique points in it should all be considered by the SE project. Thank you. Please thumb up the issue instead of writing +1 so it is easy to query the important issues

All 34 comments

Alternatively, you may consider using github to host the binaries.

https://help.github.com/articles/creating-releases/

Uploading the Release binaries to github is a great idea. Anzone know how to automate that?

I uploaded windows client(v4.24) to my github.
v4.24

There's no point of relying on a checksum -- it can be forged as well as a file itself.
Namely, I forge a file, calculate a new checksum sum and post it along with a file.

Posting the binaries to github -- we wouldn't someone from github forge a binary if they had an intention to do so?

@GildedHonour

There's no point of relying on a checksum -- it can be forged as well as a file itself.

No, it is not true. You cannot forge SHA-256 or SHA-512.
Known attack for SHA-1, was made by Google and its cost was 100K USD.

Posting the binaries to github -- we wouldn't someone from github forge a binary if they had an intention to do so?

It is question of trust.
We can trust site https://www.softether.org, its owner, site hosting provider and used COMODO certificate to identify domain.
Or we can trust https://github.com, its DigiCert certificate, repository owner, corresponding technical teams and so on.

So if you have checksum on that pages and you trust this checksum then you can calculate it for downloaded binaries and if they match you can trust this downloaded binary.

You didn't understand what I meant.

@GildedHonour

You didn't understand what I meant.

You are welcome to explain!

Clearly +1 this is a good idea. I just wanted to leave this here:

http://reddit.com/r/VPN/comments/388kpa/openvpn_vs_softether_vpn_protocol/crvs7f4

Please use secure protocols only ;-)

@ann0see The link you posted is extremely important and the critique points in it should all be considered by the SE project. Thank you. Please thumb up the issue instead of writing +1 so it is easy to query the important issues

OK. Done ;-). These issues are fixable easily, i think.

Guys. Thumb up the issue:
https://github.com/SoftEtherVPN/SoftEtherVPN/issues/369#issue-270786887

Not my comment :)

You are welcome to explain!

If I'm a hacker and I've hacked the website, I can upload a malicious version of SortEtherVPN and post a valid, new checksum along with. You wouldn't be aware if that new, malicious SortEtherVPN binary is original or malicious one. Yet, you see the correct, valid checksum on the website and assume that the binary is original. You can even download it and re-calculate it and still it'll match the one on the website, despite the fact that the SortEtherVPN binary file is a virus.

@GildedHonour if someone can hack the website, then we are in trouble, that is not the problem we are trying to solve here. The softether devs need to protect the website.

The problem we are trying to solve is that any man in the middle (eg ISP, wifi, government) can change the file for another as I download it from a http website and I currently don't have any way of verifying the checksum (from a HTTPS website).

If there is a checksum file (posted on a https website), then I can download the file insecurely, but verify it (securely) from the checksum posted on a https website. Then I know nobody has changed the file in transit.

The best way would be if the checksum file is signed with a GPG signature, which would ALSO protect from the website being hacked, as you say.

don't be paranoid, guys. if you use windows or skype or facebook or any famous antivirus - you are already watched. Android and iOS watches you too.

It's more than paranoia. Providing secure and verifiable downloads is implementing a good security principle.

@macvk this ticket is not about being watched, see other tickets for that.

This is about closing a problem that any attacker can exploit while a user is downloading softether. For example, someone sharing my cafe wifi could modify softether in-flight, and install whatever they want on my computer with the same privileges I use to install softether.

@NoahO really? how often you was attacked this way? I think less that zero times. on the other hand google play store is full of viruses.

P.S. I'm just downloaded SE binaries and see that binaries has digital signature by Softether, So when you start SE application, Windows will warn you about digital signature. if signature is correct the warning message will be blue and if signature is wrong - windows will show red warning. Signing EXE files is the only correct way to protect application under Windows.

@macvk

You can view that: https://www.krackattacks.com/

If security does not matter please tell me your bank card number and CCV.

@hardhub it's off-topic. I suggest you to not even breathe because air is full of bacilluses.

P.S. Again: the only correct way to protect application under windows - is the digital signature, SE already has it.

@macvk

It is not off topic... be sure - I am author of this issue. And you're probably a very "fat troll". In previous post I said about real MITM using vulnerability in Wi-Fi protocols. Not something theoretical, fully exploitable MITM. So secure channel (or checksum sent through secure channel) is good enough to prevent such issues.

P.S. Again: the only correct way to protect application under windows - is the digital signature, SE already has it.

You are wrong... Download CD image, analyze it, and say which executable are signed?

@macvk

Index Algorithm Timestamp
'========================================
SignTool Error: A certificate chain processed, but terminated in a root
certificate which is not trusted by the trust provider.

And what is about other files? And other OSes?
So stop flooding here... You are obviously not right.

@hardhub

  1. SE has TWO signatures.
  2. You need to use switches /pa /all
signtool.exe verify /all /pa se.exe
File: se.exe
Index  Algorithm  Timestamp
========================================
0      sha1       Authenticode
1      sha256     RFC3161
Successfully verified: se.exe

@macvk great, so we can agree it is a good idea and being done for windows.
Now let's make some progress on the other OSes, especially since a lot of Softether VPN endpoints are linux servers.

Experience has shown that changes on SoftEther website and forum are slow..

Suggestion on the short term.

  • I'll talk to Daiyuu and download the latest release of SE using my secure corporate network
  • create a new release on Github with the tag: "Ver 4.24, Build 9651, beta". This is the latest release on the SE Website
  • Upload all binaries to Github

Suggestion for the long Term:

Have a travis-ci that creates releases on demand. I only don't know whether this is possible!!

@moatazelmasry2 travis ci sounds good. My current workaround is to git clone from github and compile using a script on my servers, so this should be possible.

SE has TWO signatures.
You need to use switches /pa /all

Already see it:

Signature Index: 0 (Primary Signature)
Hash of file (sha1): 1D9A42498807173E827E2284CE59A21344A386C6

Signing Certificate Chain:
    Issued to: GlobalSign Root CA
    Issued by: GlobalSign Root CA
    Expires:   Fri Jan 28 15:00:00 2028
    SHA1 hash: B1BC968BD4F49D622AA89A81F2150152A41D829C

        Issued to: GlobalSign CodeSigning CA - G2
        Issued by: GlobalSign Root CA
        Expires:   Sat Apr 13 13:00:00 2019
        SHA1 hash: 9000401777DD2B43393D7B594D2FF4CBA4516B38

            Issued to: SoftEther K.K.
            Issued by: GlobalSign CodeSigning CA - G2
            Expires:   Fri Jan 26 10:38:18 2018
            SHA1 hash: 0495DE7CC9AB61B4172BFF1CC9F2C872FAC6D2C0

The signature is timestamped: Sun Oct 22 19:54:46 2017
Timestamp Verified by:
    Issued to: Thawte Timestamping CA
    Issued by: Thawte Timestamping CA
    Expires:   Fri Jan 01 02:59:59 2021
    SHA1 hash: BE36A4562FB2EE05DBB3D32323ADF445084ED656

        Issued to: Symantec Time Stamping Services CA - G2
        Issued by: Thawte Timestamping CA
        Expires:   Thu Dec 31 02:59:59 2020
        SHA1 hash: 6C07453FFDDA08B83707C09B82FB3D15F35336B1

            Issued to: Symantec Time Stamping Services Signer - G4
            Issued by: Symantec Time Stamping Services CA - G2
            Expires:   Wed Dec 30 02:59:59 2020
            SHA1 hash: 65439929B67973EB192D6FF243E6767ADF0834E4

Signature Index: 1
Hash of file (sha256): B1EB9061D8B7A490CA23D335893067993F9F866830E0DE1DA14C5D310A120392

Signing Certificate Chain:
    Issued to: GlobalSign Root CA
    Issued by: GlobalSign Root CA
    Expires:   Fri Jan 28 15:00:00 2028
    SHA1 hash: B1BC968BD4F49D622AA89A81F2150152A41D829C

        Issued to: GlobalSign
        Issued by: GlobalSign Root CA
        Expires:   Mon Mar 18 13:00:00 2019
        SHA1 hash: 4765557AF418C68A641199146A7E556AA8242996

            Issued to: GlobalSign CodeSigning CA - SHA256 - G2
            Issued by: GlobalSign
            Expires:   Fri Aug 02 13:00:00 2019
            SHA1 hash: 4E34C4841080D07059EFC1F3C5DE4D79905A36FF

                Issued to: SoftEther K.K.
                Issued by: GlobalSign CodeSigning CA - SHA256 - G2
                Expires:   Fri Jan 26 10:38:18 2018
                SHA1 hash: AC2FB1BB96FE740190768FC9BF20A8C8CC263E28

The signature is timestamped: Sun Oct 22 19:54:47 2017
Timestamp Verified by:
    Issued to: DigiCert Assured ID Root CA
    Issued by: DigiCert Assured ID Root CA
    Expires:   Mon Nov 10 03:00:00 2031
    SHA1 hash: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

        Issued to: DigiCert SHA2 Assured ID Timestamping CA
        Issued by: DigiCert Assured ID Root CA
        Expires:   Tue Jan 07 15:00:00 2031
        SHA1 hash: 3BA63A6E4841355772DEBEF9CDCF4D5AF353A297

            Issued to: DigiCert SHA2 Timestamp Responder
            Issued by: DigiCert SHA2 Assured ID Timestamping CA
            Expires:   Tue Jan 18 03:00:00 2028
            SHA1 hash: 400191475C98891DEBA104AF47091B5EB6D4CBCB

BUT still nothing about other OS and files.
And even in Windows... What will OS say if file is not signed and unpacked from zip archive? I guess nothing... Even with signing available a user will have to check each file instead of archive with CD (all components). And instead of hash-based integrity (embedded in many file managers) you offer the user to download Windows SDK to get SignTool?
User needs just to be sure that binary is provided by owner of the project! Any signing is just additional step... And it is not considered by 99% of users.
So secure channel is still required... to deliver binaries or deliver hash.
And for Linux it is the same. For example it can be own repository for each distro and all packages can be signed, but we still need to publish key for repo and provide that info using some secure trusted channel.

I do not think it makes sense to discuss more. I have explained my position well.
If you have opposite thoughts then we need arguments and details.
For now from your posts I can summarize only that "signing is enough to deliver valid binaries to user".
Obviously it is not true. If you have anything to say _more than signing_ - you are welcome.

I'll first try to get PR #348 through the door and then maybe we can add release step to it

@NoahO Linux has build-in signature checking just like windows. For centos you should use yum repository, for debian - apt, for freebsd - pkg.

Hi guys I created release v4.24-9651-beta on github. It contains ALL the binaries found softether-download.com:
https://github.com/SoftEtherVPN/SoftEtherVPN/releases/tag/v4.24-9651-beta

You don't have to trust me that those binaries are sane, please check for yourself by downloading the zips from softether-download.com and from github.com and compare the md5sum.

While this doesn't resolve our need of having a stable pipeline able to deliver releases, the OP of this issue wanted a secure URL to download the binaries.

That being done, I suggest we clone this issue if the uploaded binaries are sane. Please test and provide feedback

@moatazelmasry2 This looks excellent. Thank you

Hi guys. I think this task is done. I'd like to close the issue within the next 2 days if there are no objections. Cheers

Was this page helpful?
0 / 5 - 0 ratings

Related issues

dimzon picture dimzon  路  3Comments

takotakot picture takotakot  路  6Comments

vampywiz17 picture vampywiz17  路  11Comments

renatosc picture renatosc  路  3Comments

yurivict picture yurivict  路  7Comments