Live data from Hacker News

Chinese CA WoSign faces revocation after possibly issuing fake certificates

percya.com

51–60 of 116 posts

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#51
post #48

This is a pretty misleading title for a couple of reasons: 1) WoSign may face revocation (I doubt it but I don't know), but there is no evidence of that in this article. This is just one person not affiliated with a root program "calling for" it. People on the internet call for revocation of major CA roots all the time. 2) I don't really know what a "fake" cert is, it's a very strange choice of words. I would think a…

I don't really know what a "fake" cert is

You are just being pedantic. The meaning is perfectly clear, they are creating certificates for a domain and giving them to people who do not control/own that domain. Pick whatever word you like to describe this. The story is very clear.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#52
post #44
post #37

Earlier quoted context omitted.

I untrusted all Chinese-sounding CAs from "System Roots" under "Keychain Access" in OSX as soon as I got my laptop. That's what Chrome and Safari verify against.

That wouldn't have helped you in this case -- WoSign doesn't even show up in the OS X or Windows root keystores. Its certificates are (apparently) signed by StartCom. I just blacklisted StartCom's root certs. IMO for signing off on WoSign they're just as guilty, if not worse, than WoSign itself. Since they're the ones with the root cert in the OS, the buck stops there.

I attempted to remove all StartCom certs from the OS X keychain, apparently you can't do it even as root. You have to boot into the recovery partition first.

http://superuser.com/questions/1070664/security-seckeychaini...

Edit: Don't delete them, instead right click each certificate, select "Get Info", Expand the "Trust" panel, and set it to "Never Trust"

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#53
post #39

Earlier quoted context omitted.

So what is the solution to big banks and big CAs? We are just in the process of collectively creating the biggest CA the world ha sver seen.

I think we should just pull the rug out. Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, mo…

Site operators need to be more aware of which CAs they're using

How? I've got no way to judge the security / responsibility of any CA. The amount of money that they charge may have no relation to their behaviour. I don't think anyone has claimed that the CAs who issued wrong certs were charging less than their competitors. You can't blame the CA customers for this.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#54
post #52
post #44

Earlier quoted context omitted.

That wouldn't have helped you in this case -- WoSign doesn't even show up in the OS X or Windows root keystores. Its certificates are (apparently) signed by StartCom. I just blacklisted StartCom's root certs. IMO for signing off on WoSign they're just as guilty, if not worse, than WoSign itself. Since they're the ones with the root cert in the OS, the buck stops there.

I attempted to remove all StartCom certs from the OS X keychain, apparently you can't do it even as root. You have to boot into the recovery partition first. http://superuser.com/questions/1070664/security-seckeychaini... Edit: Don't delete them, instead right click each certificate, select "Get Info", Expand the "Trust" panel, and set it to "Never Trust"

You don't have to remove them, you can just set the 'Trust' setting to 'Never Trust'.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#55
post #14

Earlier quoted context omitted.

That's exactly the internet equivalent of too big to fail banks. And like for banks it is unacceptable. The internet needs its Lehman moment to become resilient again. We should let a Comodo fail.

So what is the solution to big banks and big CAs? We are just in the process of collectively creating the biggest CA the world ha sver seen.

I see two solutions to big CAs.

One is to reengineer the CA trust system to delegate limited authority to CAs (e.g. there is no good reason for a CA in the US to be able to sign certificates with Chinese TLD CNs, and vice versa).

The second is to build out the Certificate Transparency project to the point where the revocation of trust due to a mis-issued certificate is immediate, widespread, and automatic.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#56
post #39

Earlier quoted context omitted.

I think we should just pull the rug out. Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, mo…

Site operators need to be more aware of which CAs they're using How? I've got no way to judge the security / responsibility of any CA. The amount of money that they charge may have no relation to their behaviour. I don't think anyone has claimed that the CAs who issued wrong certs were charging less than their competitors. You can't blame the CA customers for this.

Very often, marketing material and the language used for for that is a good indicator on whether a particular service knows their stuff, or if they appear to peddle fluff... :)

How CAs respond to issues on these mailing lists and in bugzilla is also pretty telling.

In this particular case, there's been concerns raised for several days. An extra vigilant web site operator who sees these discussions might perhaps come to the conclusion that it would be wise to evaluate switching CAs today, perhaps.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#57
post #14

Earlier quoted context omitted.

That's exactly the internet equivalent of too big to fail banks. And like for banks it is unacceptable. The internet needs its Lehman moment to become resilient again. We should let a Comodo fail.

So what is the solution to big banks and big CAs? We are just in the process of collectively creating the biggest CA the world ha sver seen.

A viable solution to big CAs is to have all sites have their certs cross-signed by at least two different CAs. Then any single CA can be revoked without affecting any sites at all.

Note that this is also how a new CA is bootstrapped: initially the certs it issues are cross-signed by some existing CA so they work even in UAs that don't have the new CA in their trust root.

The obvious drawback is that now sites need certs signed by two CAs, and getting them to use even one CA is hard enough...

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#58
post #8

Earlier quoted context omitted.

+1 revoking a CA using the issuance date seems like the right solution

The same company also cheats on issuance date to support SHA1 signatures. I heard it on HN on another topic. Edit: source https://groups.google.com/forum/#!topic/mozilla.dev.security... Incident 2 ---------- In July 2016, it became clear that there was some problems with the StartEncrypt automatic issuance service recently deployed by the CA StartCom. As well as other problems it had, which are outside the scope of t…

This is also not very encouraging:

> R: Sorry, I don't say it clear, please forgive my bad English since my native language is Chinese. As I said this is my fault that we don't understand the Mozilla policy clearly that we don't think we need to report. But now we are clear that all mis-issued certificate case and any reported bug related system change also need to report. I and every related employee all clear now, then we can guarantee we will do it well in the future. Why we log all SSL certificate from July 5th is for full transparency to let all related parties can report to us in the first time after the certificate is issued.

Maybe employ someone with enough English knowledge to read and understand https://www.mozilla.org/en-US/about/governance/policies/secu... ?

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#59
post #45
post #29

Earlier quoted context omitted.

With CT we could in theory revoke big CAs without impacting sites currently using them.

You need the CA to either have been cooperating with CT all along, or have kept a copy of all the certs it ever issued, neither of which an incompetent CA is likely to have done. Symantec, whom one would expect to be one of the more competent CAs out there, cannot do this: https://security.googleblog.com/2015/10/sustaining-digital-c... But Google did require them to use CT for all new certificates, which I think they…

You may not be able to immediately spot a bad CA, but the more major CAs buy in to CT, the easier it is to spot fraudulent certs through fingerprint reporting. SSL clients can then choose to have a side-channel trust revocation mechanism. Once adoption snowballs, the overall level of trust in the system will rise.

The other problem is that CAs need to be regionally confined in which TLD CNs they can issue certs for.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#60

Earlier quoted context omitted.

So what is the solution to big banks and big CAs? We are just in the process of collectively creating the biggest CA the world ha sver seen.

A viable solution to big CAs is to have all sites have their certs cross-signed by at least two different CAs. Then any single CA can be revoked without affecting any sites at all. Note that this is also how a new CA is bootstrapped: initially the certs it issues are cross-signed by some existing CA so they work even in UAs that don't have the new CA in their trust root. The obvious drawback is that now sites need ce…

I was thinking the same thing. Assuming it's technically feasible I don't see this as being a huge problem. If your site is important enough that you can't have any downtime due to a CA revocation then you spend the extra time/money up front to get get cross-signed certs. If you don't care, then you just fix the problem when it comes up. If CAs start getting revoked more often then this will just become standard practice.
Post reply on HN