T09 · Insecure Skill Coding Practices
- Location
references/troubleshooting.md:85- Finding
Unauthenticated TLS Certificate Pin Bootstrap
- Content
View full analysis
Vulnerability Details
File Location:
references/troubleshooting.md, lines 85–92
Vulnerability Type: Trust-on-first-use from an unauthenticated TLS connection
Risk Level: MediumVulnerable code:
python assert b" 200" in s.recv(4096).split(b"\r\n")[0] ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT) ctx.check_hostname = False; ctx.verify_mode = ssl.CERT_NONE t = ctx.wrap_socket(s, server_hostname="registry.pilotprotocol.network") print(hashlib.sha256(t.getpeercert(binary_form=True)).hexdigest()) t.close()Technical Analysis
The documented fallback procedure obtains a new registry certificate fingerprint while explicitly disabling both certificate-chain validation and hostname verification. The resulting fingerprint is printed for use as
PILOT_REGISTRY_FINGERPRINT, making the certificate from this unauthenticated connection a future trust anchor.This path is reachable when the sandbox lacks a usable CA bundle or the existing pin no longer matches and the operator follows the documented fingerprint refresh procedure. The attacker-controlled point is the certificate presented over the network. A malicious or compromised egress proxy, or another attacker capable of intercepting the proxy tunnel, can terminate TLS using an arbitrary certificate because
ssl.CERT_NONEaccepts it.Although sending
Proxy-Authorizationto the user-configured proxy is normal proxy authentication and is not credential exfiltration, relying on that same unauthenticated network path to establish a certificate pin does not independently authenticate the registry.Attack Path
- The daemon reports an unknown-authority or fingerprint-mismatch error.
- The operator follows the documented fallback and runs the fingerprint-fetching snippet.
- An attacker controlling or intercepting the egress proxy path returns a successful
CONNECTresponse and presents an attacker-controlled TLS certificate. - Because hostn ...[truncated 893 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not derive a production trust anchor from a TLS connection configured with
CERT_NONE. - Prefer the system trust store with normal certificate-chain and hostname validation:
python ctx = ssl.create_default_context() t = ctx.wrap_socket(s, server_hostname="registry.pilotprotocol.network") - If the sandbox lacks a CA bundle, install or provide a narrowly scoped trusted CA bundle rather than disabling verification.
- Alternatively, distribute the expected fingerprint through an independently authenticated channel, such as a signed release artifact or authenticated configuration.
- If manual pin verification is unavoidable, require comparison against a fingerprint obtained through a separate trusted channel before updating
PILOT_REGISTRY_FINGERPRINT. - Document that a fingerprint observed through the same unverified proxy connection must not be trusted automatically.
- Do not derive a production trust anchor from a TLS connection configured with
