Live data from Hacker News

Chinese CA WoSign faces revocation after possibly issuing fake certificates

percya.com

101–110 of 116 posts

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#101
post #100
post #99

Earlier quoted context omitted.

Imagine a new flag for certificates issued by CAs that support CT, indicating that the domain owner (e.g. github.com) intends to continue to only use CT-capable authorities. Any certificate issued for e.g. github.com by any other CA immediately become evidence of malicious conduct attributable directly to that CA, and grounds for automated revocation of trust. I'm not sure what the lifetime of Let's Encrypt certs has…

Chrome is experimenting with something called Expect-CT[1], which allows site operators to indicate that only certificates with valid SCTs should be trusted. The implementation is quite similar to HSTS. It's report-only for now, but will probably evolve to something like Require-CT (i.e. CT enforcement) in the future. [1]: https://docs.google.com/document/d/1VDtHiKa5c96ohP_p-V1k6u83...

Sounds like the right way to go. Thanks for the pointer.

As these things develop and become increasingly security-critical parts of the protocol, it would be nice if programs like libcurl and other HTTP client libraries gained support for them.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#102
post #50

So what's the relation to StartCom/StartSSL? I remember reading some comments about half a year ago mentioning that the startssl website suddenly was hosted on Chinese IP addresses, just around the time they redesigned the web page. This seemed fishy enough back then that I finally switched from startssl to letsencrypt for non-wildcard certs and actually started paying a different CA for wildcart certs... Did the Sta…

It's funny that I got my free certs from WoSign because I didn't want to give my data to the Mossad, and now it turns out they are related. :/

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#103
Can't browsers at least restrict CAs like WoSign so that their roots are only accepted for .cn domains?

I realize that X.509 name constraints are utterly broken, but that doesn't mean that browsers can't manually restrict the domains that a given root is accepted for.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#104
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

Trust of a CA doesn't have to be binary - it could be stochastic.

Let's say that when a browser wishes to revoke a CA certificate, it chooses a timeframe for a "deprecation period". Before the deprecation period, the CA is fully trusted. After the deprecation period, it has been completely eliminated.

During the deprecation period, a browser will possibly pop up an error page rather than accepting the certificate. The probability of this happening increases as the deprecation period advances, slowly "turning up the pain" (likely exponentially or quadratically, for slow initial growth).

A reload will clear the error and load the page (or perhaps go through the probability again). Obviously it would be good if the site were notified through a header that this was happening. And user feedback will accomplish the same thing in a cruder manner.

Proactive sites would move off before the deprecation period even began. Less connected sites would get user reports and move off early in the period. Negligent sites would see their users migrate to different sites as their functionality got ever worse.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#105
post #39

Earlier quoted context omitted.

I think we should just pull the rug out. Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, mo…

Site operators need to be more aware of which CAs they're using How? I've got no way to judge the security / responsibility of any CA. The amount of money that they charge may have no relation to their behaviour. I don't think anyone has claimed that the CAs who issued wrong certs were charging less than their competitors. You can't blame the CA customers for this.

You could have backup certificates that you install when an untrustworthy CA is booted.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#106
post #2

> Possible fake cert for Github https://crt.sh/?id=29647048 https://crt.sh/?id=29805567 > Possible fake cert for Alibaba, the largest commercial site in China https://crt.sh/?id=29884704 > Possible fake cert for Microsoft https://crt.sh/?id=29805555 Yikes. If all of that is true, surely Google will permanently ban WoSign from Chrome? And I would hope Mozilla and Microsoft, too, but Google is usually the one to "play…

> Possible fake cert for Github https://crt.sh/?id=29647048 https://www.schrauger.com/the-story-of-how-wosign-gave-me-an...

Just FYI, since you only quoted one certificate. Both GitHub certificates were mine, not just the one. I created a second account for the second certificate.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#107
post #70
post #59

Earlier quoted context omitted.

You may not be able to immediately spot a bad CA, but the more major CAs buy in to CT, the easier it is to spot fraudulent certs through fingerprint reporting. SSL clients can then choose to have a side-channel trust revocation mechanism. Once adoption snowballs, the overall level of trust in the system will rise. The other problem is that CAs need to be regionally confined in which TLD CNs they can issue certs for.

> The other problem is that CAs need to be regionally confined in which TLD CNs they can issue certs for. Ryan Sleevi makes a good argument here about why that's bad policy for the internet: https://groups.google.com/d/msg/mozilla.dev.security.policy/... There are some good arguments in both directions on that thread. I do happen to like the world in which, say, Let's Encrypt is capable of issuing for any TLD. If we…

I find the arguments from "it's wrong to recognize borders on the Internet" a bit naive, or impractical. The borders recognize us, and state-sponsored attacks will continue, and have very far-reaching implications. We need better tools to fight them, including this one.

I like the discussion in that thread about how to make the scheme reasonably flexible, though. Thanks for the link.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#108
post #39

Earlier quoted context omitted.

I think we should just pull the rug out. Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, mo…

Site operators need to be more aware of which CAs they're using How? I've got no way to judge the security / responsibility of any CA. The amount of money that they charge may have no relation to their behaviour. I don't think anyone has claimed that the CAs who issued wrong certs were charging less than their competitors. You can't blame the CA customers for this.

That's a chicken-and-egg problem, but it would be solved when there's suddenly a lot of site operators with a vested interest in knowing which CAs are likely to fail and which aren't. Right now there's not a ton of interest. CAs are basically selling a fungible, commodity product, so you just buy from the cheapest ones. Searching for "best SSL certificates" thus gets you a lot of articles reviewing CAs, but largely on the basis of stuff like price and ease of issuance. Because that's what people care about.

There would be a slew of reviews of CAs, judging their perceived odds of vanishing in a puff of paperwork, if there was an interest in issuer stability. CAs themselves could probably offer value-added features like guarantees backed by outside parties (i.e. an insurance product) that would pay costs associated with certificate reissuance in the event of malfeasance or incompetence on the part of the CA.

The market would provide, but there has to be demand. Right now there's no demand, because the consequences of getting a cert from a crap issuer has, historically, been approximately zero.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#109
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

Trust of a CA doesn't have to be binary - it could be stochastic. Let's say that when a browser wishes to revoke a CA certificate, it chooses a timeframe for a "deprecation period". Before the deprecation period, the CA is fully trusted. After the deprecation period, it has been completely eliminated. During the deprecation period, a browser will possibly pop up an error page rather than accepting the certificate. Th…

Would that not just encourage your average user to click through the security warnings and ignore them, potentially numbing them to other more important warnings?

Users aren't the ones who should feel the pain of a rogue CA, we need the CA to feel the pain somehow.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#110

Earlier quoted context omitted.

You can only accept certs issued before a given date, though.

but you have to code that in every browser and hope people will be able to patch up. a revocation list from parent certificate company nuking the ca is the intended way to deal with trust breach, it should be supported everywhere, and doesn't require a full redeployment of browsers (And sometime entire OSes!) across the world.

Most major (non-embedded, I suppose) OSes have some framework for periodically updating the certificate store. It's not necessarily a full redeployment of the OS.

Mac OS and Windows both are capable of receiving new root certs via the OS update process. Apple says it updates certs approximately once per quarter:

https://www.apple.com/certificateauthority/ca_program.html

I think there is a pretty strong argument for treating a bad CA like a zero-day vulnerability and "fixing" the problem through a security update that un-trusts the cert. However, to date neither Apple nor Microsoft have been especially aggressive in this regard.

Google has taken a somewhat freer hand towards badly-behaved CAs, but they really only control Android: Chrome uses the OS's trust store, rather than its own (as Firefox does). They could presumably change this, and I'm sometimes unsure why they don't, but I guess it has to do with enterprise-environment interoperability. At some point if Chrome were to become the dominant browser, such that they could dictate terms to enterprise customers rather than the other way around (or if web apps really did take over the world to the point where the keystore outside your browser is essentially irrelevant; cf. Chromebooks), maybe they would reconsider this decision...

Post reply on HN