Laribus: Reclaiming Trust in SSL through a Social P2P Notary Network

Laribus: privacy-preserving detection of fake SSL certificates with a social P2P notary network

2015-02-17
Karl-Peter Fuchs, Dominik Herrmann, Andrea Micheloni, Hannes Federrath
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces Laribus, a decentralized P2P social notary network designed to detect local Man-in-the-Middle (MitM) attacks against SSL/TLS. It enables clients to validate certificates through diverse network vantage points using a Social Network graph, integrating Kademlia DHT, ring signatures, and threshold cryptography to achieve high privacy and availability.

TL;DR

Laribus is a decentralized, peer-to-peer (P2P) architecture designed to detect fake SSL/TLS certificates without relying on a central authority or website owner cooperation. By organizing users into "Notary Groups" based on real-world social ties and utilizing advanced cryptographic primitives like ring signatures and threshold cryptography, it provides a privacy-preserving way to verify if the certificate you see is the one the rest of the world sees.

The Problem: The Fragility of the "Any-to-Any" Trust Model

The modern web relies on Certificate Authorities (CAs). However, the X.509 model has a fatal flaw: any CA can sign for any domain. If a single CA—out of more than 650 trusted by browsers—is compromised or coerced, it can issue a "valid" fake certificate for Google, PayPal, or any other site.

This enables Man-in-the-Middle (MitM) attacks that are invisible to the user. Previous attempts to fix this, like Perspectives or Convergence, introduced "Notaries"—servers that fetch certificates from different network locations. But these notaries become central points of failure and, more importantly, privacy nightmares that know exactly which sites you visit.

Methodology: Social Trust + Cryptographic Rigor

Laribus shifts the paradigm from "Trust an Organization" to "Trust Your Friends." It operates across three distinct layers:

  1. Social Network Layer: A graph of real-world friendship relations. This limits the influence of "Sybil" attackers (fake accounts) because they cannot easily enter a "Trusted Core."
  2. Notary Group Layer: Virtual notaries formed by these cliques. They use Threshold Signatures so that even if some friends are offline, the group can still function.
  3. Storage Layer (DHT): A global Kademlia-based Distributed Hash Table that acts as a cache for "Certificate Validation Records" (CVRs).

Laribus Architecture

The "How it Works" Intuition

When Alice visits a site, she doesn't just trust the certificate presented. She performs a Direct Query to a Notary Group (potentially her friends). To prevent her friends from knowing her browsing habits, she uses Layered Encryption (Sphinx) and Ring Signatures. The Notary Group fetches the certificate from their vantage point, hits a consensus via majority vote, and signs the result.

Cryptographic Innovations

The technical "secret sauce" of Laribus lies in how it balances Availability with Security:

  • Dynamic Threshold RSA: Traditional threshold schemes are static; if the group size changes, you need a new key. Laribus uses a scheme by Lesueur et al. that allows shares to be split or merged dynamically.
  • Privacy-Aware Lookups: Instead of asking the DHT for hash(google.com), which leaks the destination, users perform Range Queries, fetching a subtree of results to provide k-anonymity.

Notary Signature Process

Evaluation: Is it Practical?

A common critique of P2P systems is "Churn"—users going offline. The authors conducted a feasibility study modeling different user types (Casual, Power, Office).

  • Availability: By setting a threshold of (requiring half the group to be online), groups of 6 or more members stay operational in over 50% of cases.
  • Latency: High-performance elliptic curve libraries (Curve25519) keep routing and encryption overhead below 1 second, making it viable for real-time browsing.

Availability Simulation

Critical Analysis & Conclusion

Laribus is a significant step toward Blocking-Resistant security. Unlike global lists or central servers, an adversary cannot simply block "The Notary." However, it does face the "CDN Problem"—where legitimate sites serve different certificates based on geography.

Takeaway: Laribus proves that we don't need to choose between privacy and security. By leveraging the existing social fabric and robust P2P algorithms, we can build a web where "Trust" is decentralised, transparent, and resilient to even state-level actors.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Social Network Graphs or Friendship Trees to improve Sybil-resistance in Peer-to-Peer security protocols.
  • Which study first introduced the formal concept of 'Certificate Transparency', and how does the Laribus DHT timeline differ in its handling of split-world attacks?
  • Explore how contemporary Zero-Knowledge Proof (ZKP) techniques could be applied to Laribus-style notary queries to further enhance user privacy without relying on layered encryption.
Contents
Laribus: Reclaiming Trust in SSL through a Social P2P Notary Network
1. TL;DR
2. The Problem: The Fragility of the "Any-to-Any" Trust Model
3. Methodology: Social Trust + Cryptographic Rigor
3.1. The "How it Works" Intuition
4. Cryptographic Innovations
5. Evaluation: Is it Practical?
6. Critical Analysis & Conclusion