Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

11–20 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#12
I like this part at the end:

> In addition, Mozilla will:

> add all of the Macau certificates to OneCRL immediately;

> and no longer accept audits carried out by Ernst & Young (Hong Kong).

If you don't hold the auditors responsible, this will happen again. If you do hold the auditors responsible, you might prevent some of this.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#13
>We also hope the public can see that when there are allegations of CA wrongdoing, Mozilla is committed to a fair, transparent and thorough investigation of the facts of each case.

I'm very happy to see the way Mozilla handled this incident, both with the process and the conclusion. I have a moderate trust in the CA ecosystem as a whole, but I'm glad to see that overwhelming incompetence, if not outright maliciousness, does have consequences even to big CAs.

At first though the proposed one year timeout can seem a little short given the impressive list of reported issues, but the conditions given for re-acceptance are strict enough that passing could only indicate a radical change in methodology, at which point it would only make good sense to consider a re-inclusion.

In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed, I think we would have reason to feel marginally safer on the Internet.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#14
post #5

This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…

The EFF has had similar programs in the past and I generally believe them to be a reputable organization.

https://www.eff.org/observatory

A donation funded, publicly audited, transparency report seems like a good idea to me.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#15
If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#16
Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs.

Later:

Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China.

More specifically:

https://twitter.com/pzb/status/780456712562024448

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#17

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

It's not a 1 year suspension. It's a 1 year complete ban, then they may apply again from scratch, with extra requirements.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#18

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor (raises hand! pick me!) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear.

StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, it would primarily punish StartCom's customers, and not WoSign, which as a business is primarily concerned with forward revenue.

You see this as leniency, but I see it as a powerful step forward. The browsers and CAs had previously been locked in a Mexican Standoff, with abusive CAs fully aware of the leverage their userbases offered them.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#19
post #8

Completely and utterly fail your job, lie about it and use deceiving tactics? And all they are getting is a 1 year suspension and none of the certificates are becoming untrusted. The auditors got a bigger punishment by being banned completely from Mozilla's trusted auditors. Should just revoke them completely. Such incompetence and/or malice should not be allowed on such a crucial piece of infrastructure.

Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…

Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#20
post #10
post #5

This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…

> Google detecting further abuse of notBefore via Certificate Transparency You don't need to rely on Google. All certs issued by WoSign since January 1st, 2015 should be on WoSign's own Certificate Transparency log from which you can download them. StartCom is logging all new certs too, but I don't know for sure if they pushed all older ones too. If you ever encounter a cert that isn't on the list, that's definitive…

> You don't need to rely on Google ... should be on WoSign's own Certificate Transparency log which you can download

Given that the behaviours being documented include falsifying data (backdating certificates to get around SHA1 retirement), I would prefer to at least use information from Google (or another third party) for the purpose of verification, rather than just relying on information sourced from WoSign/StartCom.

Post reply on HN