Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

111–120 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#111
Now that StartSSL is effectively deceased, is there a commercial CA that supports the ACME protocol? Or is the ACME protocol a vanity project unique to Let's Encrypt?

I manage several dozen certificates; I was very pleased when StartSSL offered an automated API to work with. Despite their flaws, they offered EV certs, wildcards, and automated one-shots, and it was very convenient.

I'd gladly pay for this functionality, preferably while supporting standards-based ACME functionality... but so far it seems Let's Encrypt is the only one playing that game, and their featureset is crap for anything but their very narrow use case.

Any advice, HN?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#112
post #10
post #5

This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…

> Google detecting further abuse of notBefore via Certificate Transparency You don't need to rely on Google. All certs issued by WoSign since January 1st, 2015 should be on WoSign's own Certificate Transparency log from which you can download them. StartCom is logging all new certs too, but I don't know for sure if they pushed all older ones too. If you ever encounter a cert that isn't on the list, that's definitive…

You need to rely on someone who sees certs in the wild that aren't in the CT log and complains. Chrome is capable of doing that (I don't know if it actually does), as are Google's web crawlers. I don't think Mozilla has anything that does that.

It is true that, provided you have a CT log, it is append-only, and data can never leave the log file. But you need to make sure the right data is in it at some point.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#113
post #18

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…

Yeah but the existing certs are still out there. While it's great that a company is being punished, this completely ignores the fact that we have no idea what they've signed, and short of laboriously checking the trust path of every single certificate you encounter there's no way to know if the cert you're looking at at any given moment came from them or not. And worse yet, the bigger problem is there's not a practical way to actually yank all of the certificates they signed that will work for arbitrary clients who don't know anything about this process to begin with and just look for a lock in the address bar, if that.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#114
post #80
post #26

Earlier quoted context omitted.

They're not "killing" anyone. They have reasonable doubt that the CA has misrepresented the truth and engaged in practices that violate the rules set forth by the CAB and those for inclusion in the Mozilla trust store. There will have to be consequences for else it means nothing. They're also very clear that they do not intend to invalidate any already issued certificates, only new ones after a specific, yet to be de…

They're absolutely killing WoSign/Startcom. It's totally justified, but it's what they're doing.

WoSign/Startcom signed their own "death warrant" by engaging in fraud.

I only wish death sentences for companies participating in blatantly fraudulent activities would be issued more regularly by regulatory agencies.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#115
post #107
post #105

I remember that there was some talk about double voting (WoSign and StartCom not being separate entities, but voting with two votes) in the mailing list. Is there a reason as to why this event hasn't been included in the document? edit: https://groups.google.com/forum/#!topic/mozilla.dev.security... > "In no case were these the deciding votes."

The issue you're describing is a concern for the CA/B Forum, not really all that relevant for Mozilla/mozilla.dev.security.policy. That being said, the CA/B Forum seems to be discussing the issue[1]. [1]: https://twitter.com/sleevi_/status/780454860676149248

Thank you, though the Qihoo relationship is not what I was referring to.

I actually meant executing two votes in the CA/B Forum. As the connection between WoSign and StartCom was only incidentally found while investigating the other issues, I am questioning if there may be more dark sheep in the herd of CAs... we may just haven't looked hard enough. Do the Audit Requirements include checking for such relationships?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#116
post #106
post #105

I remember that there was some talk about double voting (WoSign and StartCom not being separate entities, but voting with two votes) in the mailing list. Is there a reason as to why this event hasn't been included in the document? edit: https://groups.google.com/forum/#!topic/mozilla.dev.security... > "In no case were these the deciding votes."

It's in the wiki https://wiki.mozilla.org/CA:WoSign_Issues

Could you please refer to the actual Issue? I can neither find anything related to the CA/B-Forum voting fraud nor to the yet unresolved Qihoo relationship.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#117

Nuke it from orbit. The whole idea of PKI is Broken and Wrong and confuses two different goals. Here's a fun one I noticed: Wells Fargo and several other banks are CAs. This is idiotic. The "logic" behind PKI dictates that it's a third party identifying my bank to me. If banks themselves are CAs even that fig leaf doesn't mean much. We have known bad actors in the pool of widely accepted CAs, right now. There's no se…

> The "logic" behind PKI dictates that it's a third party identifying my bank to me

Not true. The third party is an operational detail to scale, there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they?

You're suggesting that you don't trust your bank's opinion on what websites belong to them, but do trust some third party's? Even if this made any sense, the third party is doing nothing but taking the bank's word for it, if a bank for some reason _wanted_ to affirm that some random domain was EV-certified as Wells Fargo, they surely could, even if they weren't the CA -- that's just not a threat the CA model is designed against.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#118

Nuke it from orbit. The whole idea of PKI is Broken and Wrong and confuses two different goals. Here's a fun one I noticed: Wells Fargo and several other banks are CAs. This is idiotic. The "logic" behind PKI dictates that it's a third party identifying my bank to me. If banks themselves are CAs even that fig leaf doesn't mean much. We have known bad actors in the pool of widely accepted CAs, right now. There's no se…

OK, so what do you want to happen starting tomorrow morning?

* All HTTPS sites show up as trusted. Woohoo!

* All HTTPS sites show up as untrusted, people are encouraged to switch to HTTP. Woohoo!

* All HTTPS sites use trust-on-first-use, which means that we have a date and time announced when MITM attacks are particularly effective and will persist for a very long time.

* All HTTPS sites are untrusted, except for those that already have certificate pins hard-coded in the browsers' source, and excluding those that are pinning their CAs (because CAs are Broken and Wrong), which means the only websites you can access are Google's properties via Google's browser. Awesome!

* Replace HTTPS with PGP. Only people who know how to use PGP correctly get to use secure web traffic.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#119

Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?

Do people use S/MIME with the standard (web-based) trust stores? If you're using it with a small group of people you're in communication with, you can always generate your own CA pretty easily with the openssl command.

(Except for the part about the openssl command, this is what Exchange does: everyone joined to an Active Directory domain gets config from the AD servers, so AD generates its own CA for S/MIME certs and tells its users about it.)

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#120
post #19
post #8

Earlier quoted context omitted.

Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…

Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.

Is user security actually improved by causing all WoSign- and StartCom-signed sites to show certificate warnings? It seems to me like it is reduced:

1. Your browser is no longer capable of telling you whether it's a legitimate WoSign- or StartCom-signed certificate (they behaved inappropriately, but they never intentionally signed one site's cert for someone not affiliated with the site) or a completely random certificate.

2. People clicking through SSL warnings is one of the bigger risks to user security in practice. Teaching people (especially people in their target markets) that they need to click through these warnings to get to their websites will have a very long-term negative effect on user security for a long time to come.

Post reply on HN