Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

31–40 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#31

A clear and detailed report. The conclusion seems both transparent and fair. It would be very difficult for many customers of StartCom/WoSign if they were immediately revoked. Hopefully this news spreads far enough that the reputation of StartCom/WoSign will generally include this information. I am saving this as a reference in the event I ever need to write a technical report. This style is so much easier to read th…

Yes, we are very fortunate to have Let's Encrypt now.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#32
I think this is very well handled on the part of Mozilla, especially with respect to existing customers.

What's missing, which admittedly is not Mozilla's job, is to inform any existing customers that will have to renew during the time WoSign and StartCom are suspended. If they just get an invoice and pay it or are set-up with auto-renew, they'll unknowingly get certificates that aren't valid for the remainder of the suspension (or indefinitely, if WoSign/StartCom if violates Mozilla's requirements).

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#33
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

Mozilla is killing StartCom. Chrome has not announced a decision yet, although I predict that they will also distrust.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#34
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

Behaviours of StartCom and its owner WoSign that are against the accepted rules of the industry they work in, in industry for which trust if key, is killing StartCom. Being popular does not give you the right to expect transgressions to be ignored. I used to use StartCom and even recommend them (it was an inexpensive way to get wildcard and multi-domain certificates). Since LetsEncrypt they have far less relevance, a…

By "huge", I meant:

https://news.ycombinator.com/item?id=12583390

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#36
post #19
post #8

Earlier quoted context omitted.

Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…

Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.

You forget things like certificate pinning which can make sites inaccessible for long durations of time if the user doesn't visit said website during this transition period.

I'm not super convinced about the user security argument either. Sure, they backdated SHA-1 certificates and that's nasty but those certificates still expire at a reasonable time in the near future and will soon enough not be accepted by browsers at all or show up with scary UI warnings. That said I don't agree or condone what they did.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#37
post #11

I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?

Considering I believe one of the writers of this was from Google, I guess we can assume they'll likely follow? With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.

Does Chrome maintain its own trusted certificate list on any platform?

IIRC, it uses the OS's trust store on Windows and macOS, and NSS (so, Mozilla's trust store) on Linux. So, it's up to Apple and Microsoft to handle this for Chrome users on those platforms.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#39
While most of the doc focused on StartCom/WoSign, I thought this bit at the end was interesting:

> no longer accept audits carried out by Ernst & Young (Hong Kong).

To reject audits from E&Y.... It makes me wonder about the transparency and trust we put in the auditors as being a key part of CA validation process.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#40
post #33
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

Mozilla is killing StartCom. Chrome has not announced a decision yet, although I predict that they will also distrust.

It's pertinent in this matter that one of the authors of the report works on the Chromium TLS stack.

But it's not clear to me whether Chrome has an independent CA program. They use the Microsoft CA store on Windows, and at some point were using NSS (and hence the Mozilla certs) on Unixes. I presume they can always just additionally block this CA in Chrome, though.

Post reply on HN