WoSign and StartCom: Mozilla’s proposed conclusion
11–20 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#12> In addition, Mozilla will:
> add all of the Macau certificates to OneCRL immediately;
> and no longer accept audits carried out by Ernst & Young (Hong Kong).
If you don't hold the auditors responsible, this will happen again. If you do hold the auditors responsible, you might prevent some of this.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#13I'm very happy to see the way Mozilla handled this incident, both with the process and the conclusion. I have a moderate trust in the CA ecosystem as a whole, but I'm glad to see that overwhelming incompetence, if not outright maliciousness, does have consequences even to big CAs.
At first though the proposed one year timeout can seem a little short given the impressive list of reported issues, but the conditions given for re-acceptance are strict enough that passing could only indicate a radical change in methodology, at which point it would only make good sense to consider a re-inclusion.
In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed, I think we would have reason to feel marginally safer on the Internet.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#14This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…
https://www.eff.org/observatory
A donation funded, publicly audited, transparency report seems like a good idea to me.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#15Re: WoSign and StartCom: Mozilla’s proposed conclusion
#16Later:
Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China.
More specifically:
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#17A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#18A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, it would primarily punish StartCom's customers, and not WoSign, which as a business is primarily concerned with forward revenue.
You see this as leniency, but I see it as a powerful step forward. The browsers and CAs had previously been locked in a Mexican Standoff, with abusive CAs fully aware of the leverage their userbases offered them.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#19Completely and utterly fail your job, lie about it and use deceiving tactics? And all they are getting is a 1 year suspension and none of the certificates are becoming untrusted. The auditors got a bigger punishment by being banned completely from Mozilla's trusted auditors. Should just revoke them completely. Such incompetence and/or malice should not be allowed on such a crucial piece of infrastructure.
Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#20This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…
> Google detecting further abuse of notBefore via Certificate Transparency You don't need to rely on Google. All certs issued by WoSign since January 1st, 2015 should be on WoSign's own Certificate Transparency log from which you can download them. StartCom is logging all new certs too, but I don't know for sure if they pushed all older ones too. If you ever encounter a cert that isn't on the list, that's definitive…
Given that the behaviours being documented include falsifying data (backdating certificates to get around SHA1 retirement), I would prefer to at least use information from Google (or another third party) for the purpose of verification, rather than just relying on information sourced from WoSign/StartCom.