Live data from Hacker News

Chinese CA WoSign faces revocation after possibly issuing fake certificates

percya.com

11–20 of 116 posts

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#11
post #4

Earlier quoted context omitted.

[deleted]

I believe this is done by not accepting any certificate issued past date X. This way the old certificates keep working, while the new ones don't.

This is problematic here, because WoSign is also known to have issued a certificate in July 2016 backdated to December 2015:

https://groups.google.com/d/msg/mozilla.dev.security.policy/...

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#12
post #8
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

+1 revoking a CA using the issuance date seems like the right solution

It would certainly be better than nothing, yes.

But prior to March 2015, CAs could issue certs valid for up to 5 years. So even if browsers stopped accepting WoSign certs with an issuance date after today, WoSign could still issue certs "issued March 2015 valid until to March 2020" and browsers would accept them.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#13
post #2

> Possible fake cert for Github https://crt.sh/?id=29647048 https://crt.sh/?id=29805567 > Possible fake cert for Alibaba, the largest commercial site in China https://crt.sh/?id=29884704 > Possible fake cert for Microsoft https://crt.sh/?id=29805555 Yikes. If all of that is true, surely Google will permanently ban WoSign from Chrome? And I would hope Mozilla and Microsoft, too, but Google is usually the one to "play…

Wosign is not in the list of default CAs on the Mac, according to Keychain, so if you are using Chrome on a Mac, since Chrome only uses the system's root certs, you should be safe as long as you don't go add that root cert into Keychain. Wosign is in Firefox however, so Mozilla needs to do something about this.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#14
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

That's exactly the internet equivalent of too big to fail banks. And like for banks it is unacceptable. The internet needs its Lehman moment to become resilient again. We should let a Comodo fail.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#17
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

Give them a month, publicize in the relevant places, and that's that. If a site gets caught out it's not the end of the world. If they have big money on the line then they can afford to have someone on staff that keeps up with this stuff.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#18
post #8

Earlier quoted context omitted.

+1 revoking a CA using the issuance date seems like the right solution

It would certainly be better than nothing, yes. But prior to March 2015, CAs could issue certs valid for up to 5 years. So even if browsers stopped accepting WoSign certs with an issuance date after today, WoSign could still issue certs "issued March 2015 valid until to March 2020" and browsers would accept them.

If they start putting fake dates on the certs then the nuclear option is the only option. They are in the business of selling trust and they're outright lying on their only product? That's untenable.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#19
post #13
post #2

> Possible fake cert for Github https://crt.sh/?id=29647048 https://crt.sh/?id=29805567 > Possible fake cert for Alibaba, the largest commercial site in China https://crt.sh/?id=29884704 > Possible fake cert for Microsoft https://crt.sh/?id=29805555 Yikes. If all of that is true, surely Google will permanently ban WoSign from Chrome? And I would hope Mozilla and Microsoft, too, but Google is usually the one to "play…

Wosign is not in the list of default CAs on the Mac, according to Keychain, so if you are using Chrome on a Mac, since Chrome only uses the system's root certs, you should be safe as long as you don't go add that root cert into Keychain. Wosign is in Firefox however, so Mozilla needs to do something about this.

They're cross-signed by StartCom, which is trusted by MacOS.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#20
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

> their only crime is using a crap CA

thing is the whole castle is built upon trust.

if you don't punish crap CA and ppl who don't do research first, things will deteriorate rapidly.

Post reply on HN