How does your browser know that the padlock is not a fake?
Encryption is easy to do and hard to trust. Your browser relies on a few dozen organisations to vouch for every site, and in 2011 one of them was hacked.
▶ Start the storyThe padlock means your browser checked a certificate, a digital document that certifies the ownership of a public key by the named website. A certificate authority, or CA, issues it and acts as a trusted third party, trusted both by the site's owner and by the visitor who relies on it.
Encryption alone is not enough. When you connect, your browser and the site use a handshake with an asymmetric cipher to establish a shared key, and then use that key to encrypt the rest of the conversation with a symmetric cipher. But a malicious party sitting on the route could pretend to be the target server, the classic man-in-the-middle attack. A certificate is what makes that fake detectable. Browsers include a built-in set of trusted CA certificates, and since the browser already holds each authority's public key, it can verify the signature on the certificate the site presents. An impostor could copy a real site's certificate, but without the matching private key it cannot create the signature needed to prove it is the real site.
Step 1: Handshake starts
Browser and site begin to set up a connection
Step 2: Certificate
The site presents a certificate signed by a CA
Step 3: Trusted list
The browser checks the signature against CAs it already trusts
Step 4: Proof of the private key
Only the real site can complete the handshake
Step 5: Encrypted session
Traffic is encrypted with a shared session key
The system has one structural weakness: any CA a browser trusts can issue certificates for any domain it likes, and they will be accepted as valid whether they are legitimate or not. In June 2011 the Dutch CA DigiNotar was hacked and issued hundreds of fraudulent certificates, some of which were used for man-in-the-middle attacks on Iranian Gmail users. After more than 500 fake certificates were found, browser makers blacklisted all DigiNotar certificates, and the company was declared bankrupt that September.
Quiz me
0/3
Recap
Encryption protects the line; certificates prove who is on the other end; public logs watch the signers.
💡 A trick to remember it · A padlock is a notary's stamp: it only means something while you trust the notary, so we now keep a public ledger of every stamp.
Surprising fact · Any trusted CA can issue a certificate for any domain, which is why DigiNotar's 2011 breach was so serious.
Connects to
- 📖 How does your browser find a website from just its name?
- 🧭 How did one maintenance command take Facebook off the internet for hours?
- 🔓 Why did an NBA team hand over every employee's tax forms to a scammer?
- 🔑 How do computers tell a file hasn't been changed?
- 📦 How does the internet deliver your data without ever giving you a line of your own?
- 🔐 How can two strangers agree on a secret while everyone is listening?
- Rsa cryptosystem
Sources (4)
No source, no claim. Every fact in this lesson (19 claims) cites at least one of these.