Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

1–10 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#3

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

It's generous to the customers who currently have existing, valid WoSign or StartCom certificates. It's not very generous to WoSign or StartCom as continuing profitable businesses, because if I were paying either of these companies for certificates, I'd be looking for someone else to pay when it comes time to renew. This is exactly what you want.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#4

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

With a "play by the rules or you're out" attached.

It's more lenient than some might want, but it avoids the decision being controversial and perhaps lessens the chance that it is seriously challenged.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#5
This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert.

It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should really be participating in CT themselves so they have more options here. Is there anything the community can do to help (e.g., run more log servers)?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#6
Completely and utterly fail your job, lie about it and use deceiving tactics?

And all they are getting is a 1 year suspension and none of the certificates are becoming untrusted. The auditors got a bigger punishment by being banned completely from Mozilla's trusted auditors.

Should just revoke them completely. Such incompetence and/or malice should not be allowed on such a crucial piece of infrastructure.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#7
A clear and detailed report. The conclusion seems both transparent and fair. It would be very difficult for many customers of StartCom/WoSign if they were immediately revoked. Hopefully this news spreads far enough that the reputation of StartCom/WoSign will generally include this information.

I am saving this as a reference in the event I ever need to write a technical report. This style is so much easier to read than a typical "official" report from police, the FBI, or similar organizations.

I don't have any StartCom or WoSign certificates right now, but I did in the past. It was nice to be able to get a certificate that browsers accepted, without needing to pay for it. I'm glad the landscape has changed.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#8

Completely and utterly fail your job, lie about it and use deceiving tactics? And all they are getting is a 1 year suspension and none of the certificates are becoming untrusted. The auditors got a bigger punishment by being banned completely from Mozilla's trusted auditors. Should just revoke them completely. Such incompetence and/or malice should not be allowed on such a crucial piece of infrastructure.

Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products.

Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when choosing a certificate seller. But revocation hurts other people (website owners and visitors) more than the CA, and it doesn't seem totally obvious that it's worth it.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#9
post #8

Completely and utterly fail your job, lie about it and use deceiving tactics? And all they are getting is a 1 year suspension and none of the certificates are becoming untrusted. The auditors got a bigger punishment by being banned completely from Mozilla's trusted auditors. Should just revoke them completely. Such incompetence and/or malice should not be allowed on such a crucial piece of infrastructure.

Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…

Is there a compiled listing of all CA audits (good and bad) and "offenses" so a prospective customer might be able to choose a CA based on past performance rather than marketing materials?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#10
post #5

This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…

> Google detecting further abuse of notBefore via Certificate Transparency

You don't need to rely on Google. All certs issued by WoSign since January 1st, 2015 should be on WoSign's own Certificate Transparency log from which you can download them. StartCom is logging all new certs too, but I don't know for sure if they pushed all older ones too. If you ever encounter a cert that isn't on the list, that's definitive proof that they are backdating again.

The list of certificates is too large for Mozilla to include a list of hashes in Firefox, but it might be a nice opportunity for a Firefox add-on.

Post reply on HN