Earlier quoted context omitted.
Cert rotation every 3 months is a feature, IMHO. It encourages you to automate everything related to rotation.
I got downmodded before for saying this, but I still feel this way: Automating this simply means that if someone hacks your machine, they also have full access to generate any certs they like. I don't consider this a positive thing. You can separate the generation onto another machine, but it's much more complicated, and the default install is not that way. I have yet to hear any useful reason to rotate the key.
Why I stopped using StartSSL (Hint: it involves a Chinese company)
101–110 of 187 posts
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#102Earlier quoted context omitted.
Cert rotation every 3 months is a feature, IMHO. It encourages you to automate everything related to rotation.
I got downmodded before for saying this, but I still feel this way: Automating this simply means that if someone hacks your machine, they also have full access to generate any certs they like. I don't consider this a positive thing. You can separate the generation onto another machine, but it's much more complicated, and the default install is not that way. I have yet to hear any useful reason to rotate the key.
Another side-effect is that you don't need to manage revocation stuff as diligently, because certificates automatically expire shortly. The window during which a certificate is valid is extremely short and recent, which means there is less chance that a problem happens. when that probability increases (as a result of being older), certificates become automatically invalid.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#103Earlier quoted context omitted.
Like it or not, they do have a crack team of engineers. 90%+ of the Windows kernel hackers in China have worked, or still is with Qihoo.
Source?
Palo Alto Networks - 34
Qihoo/360 - 27
FireEye - 14
Tencent - 14
Trend Micro - 12
Fortinet - 7
McAfee - 2
VMware - 2
Kaspersky - 1
They are a pretty unsavory company but they really know what they are doing.
Source: https://technet.microsoft.com/library/security/dn903755.aspx
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#104Chinese company is not a red flag. but Qihoo is. The company has known bad reputation. a. they labeled their own browser as a Microsoft security update, which triggered MS investigation b. they cheated on the anti-virus lab testing and got banned. ....etc.
Would like to add Baidu isn't better, too. Example, try search proprietary software, say 'Autocad', first few results are always pirate sites, while google will show the Autodesk site and the wikipedia post. Recently Baidu also under the spotlight for monetizing illness-related forums[1]. The issue is some patients accused the Internet giant selling their private info to _unqualified_ private hospitals. These hospita…
Unless this[0] is the Autocad office in China (which I highly doubt), there's absolutely no link to the Autodesk website on the first result page.
In fact, their instant answer when you search for Autocad is downloadable version of Autocad for Win/Mac/iOS. I don't have a Win/Mac computer with me at the moment, so I can't verify are those legit trial versions or pirated ones, but the iOS one points to the legit version on Apple's store.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#105Earlier quoted context omitted.
I should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication. I know it's more common in enterprise situations. I'm supposed to have a workflow to backup my browser client certificates just for one site? It's not their fault that browsers mostly have poor UI for handling client certs, but it is their fau…
> I should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication. I don't know what you have been doing the last 20 years on the web (and I'll assume it's more than just surfing facebook), but it's not entirely uncommon, and I've encountered it several places. Symantec's CA uses it. My online bank used to…
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#106Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#107You are borrowing someone else's trust. You are hoping that the company you get a cert from won't pretend to be you. There is no technical mechanism to stop this, no matter where the parent company is based.
Also the other thing to note is that virtually all communications companies have some sort of government involvement regardless of where they are based.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#108Earlier quoted context omitted.
> I should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication. I don't know what you have been doing the last 20 years on the web (and I'll assume it's more than just surfing facebook), but it's not entirely uncommon, and I've encountered it several places. Symantec's CA uses it. My online bank used to…
The fact I'm on Hacker News should probably give you an idea. I know it's relatively common on corporate intranets, but I don't use those. I can assure you that I've used lots of CAs, banking sites, VPN providers, registrars, hosting providers (and plenty of others) and made no specific effort to avoid them, and StartSSL is (almost) the only one I've found. I've remembered that the UK Government Gateway used to use t…
To be clear about that: My point about half-assed was your seeming unwillingness to back up client-certificates which gives full access to your real certificates and (in some cases) private certificate keys.
Unless on Windows (where StartSSL has its private keys marked non-exportable in the certificate store, sic), doing such a backup takes almost no effort. There's no excuse for going all the way through to get a cert and then not bothering backing up these client-certs too.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#109It would be so easy for NSA/GCHQ to recruit or place an "agent" inside of any Western CA or ISP they wanted. There is even evidence in recent years that this has been happening.
http://www.theregister.co.uk/2015/09/21/symantec_fires_worke...
This was merely the most recent incident. Yes Symantec covered it up quite nicely and framed it as a test that went wrong (the Russian's used that excuse with Chernobyl) but there is no evidence those "rogue employees" were not acting for the state i.e. the USA.
There was also the recent incident with Juniper networks and the state-sponsored backdoor that had been present in much of their network gear for a few years. See: http://www.wired.com/2015/12/researchers-solve-the-juniper-m...
Still think the West CA's and ISPs are better than Chinese ones?
The only question you need to ask yourself is: Which government would you rather have eyes on your data? One might surmise that if you have something to hide from Western eyes then use a Chinese provider. And if you have something to hide from Chinese eyes then use a Western provider. The balance of probabilities, I believe, backs this up.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#110Chinese company is not a red flag. but Qihoo is. The company has known bad reputation. a. they labeled their own browser as a Microsoft security update, which triggered MS investigation b. they cheated on the anti-virus lab testing and got banned. ....etc.
I've worked with a company that at least 30% of our user base uses Qihoo brower. They blocked few of our domains and now, someone from Qihoo asked us to pay so that they will unblock our domains.