Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

131–140 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#131

Earlier quoted context omitted.

> The "logic" behind PKI dictates that it's a third party identifying my bank to me Not true. The third party is an operational detail to scale, there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? You're suggesting that you don't trust your bank's opinion on what websites belong to them, but do trust some third party's? Even if this made any sense, the thir…

there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…

I am having a really hard time following this argument. The CA isn't vouching for the content of your HTTPS requests.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#132
post #118

Earlier quoted context omitted.

OK, so what do you want to happen starting tomorrow morning? * All HTTPS sites show up as trusted. Woohoo! * All HTTPS sites show up as untrusted, people are encouraged to switch to HTTP. Woohoo! * All HTTPS sites use trust-on-first-use, which means that we have a date and time announced when MITM attacks are particularly effective and will persist for a very long time. * All HTTPS sites are untrusted, except for tho…

Mostly #5, with some of #4. We have known bad certs in the wild (including for Google) so the "security" PKI offers us is just theater. I think the theater should end, which might actually get people off their asses to fix the real problem and stop outsourcing it to shady rent-seeking companies.

If the security the CAs offer is "just theater", go spoof DNS and phish Bank of America logins; you should be able to trick users just by rolling self-signed certificates.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#133

Earlier quoted context omitted.

there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…

I am having a really hard time following this argument. The CA isn't vouching for the content of your HTTPS requests.

No, the only thing the CA vouches for is that the other party is who they claim to be, which 99% of the time doesn't matter because I don't trust who they claim to be any more than I trust someone impersonating who they claim to be.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#134
post #65

Earlier quoted context omitted.

Isn't that only E&Y Hong Kong, though? Really at this point I don't know why anybody in China, or any country known for its corruption, should be accepted as auditors.

You're painting 1 billion people with a rather broad brush.

He's only painting the authorities of those people with a broad brush. If something was confirmed from a chinese authority (private or public) would you trust that more, less, or the same due to the 'chinese' specifier?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#135

Earlier quoted context omitted.

Mostly #5, with some of #4. We have known bad certs in the wild (including for Google) so the "security" PKI offers us is just theater. I think the theater should end, which might actually get people off their asses to fix the real problem and stop outsourcing it to shady rent-seeking companies.

If the security the CAs offer is "just theater", go spoof DNS and phish Bank of America logins; you should be able to trick users just by rolling self-signed certificates.

You do know that BofA is one of the organizations with verified bad certificates in the wild, right? This isn't just a theoretical worry. That's why it's "theater": we know that right now there are valid but bad certificates for a depressing number of entities.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#136
post #56

Earlier quoted context omitted.

Why are you using S/MIME? You can still get free S/MIME certs from Comodo.

Wasn't Comodo on the list of bad CAs one should avoid too?

You're probably thinking of https://news.ycombinator.com/item?id=11961034

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#137
post #69

Earlier quoted context omitted.

If I might ask, why don't you like them?

They are a political organisation and their ideas conflict with mine. I don't keep a strong boycott on them, but I don't want to support their products, that's all.

I'd be very interested to know which of the EFF's political positions you object to, but it appears pretty clear you're avoiding answering that question...

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#138

Earlier quoted context omitted.

If the security the CAs offer is "just theater", go spoof DNS and phish Bank of America logins; you should be able to trick users just by rolling self-signed certificates.

You do know that BofA is one of the organizations with verified bad certificates in the wild, right? This isn't just a theoretical worry. That's why it's "theater": we know that right now there are valid but bad certificates for a depressing number of entities.

Feel free to win the argument by presenting me with a Bank of America certificate that my browser will validate, which wasn't generated by Bank of America.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#139

Now that StartSSL is effectively deceased, is there a commercial CA that supports the ACME protocol? Or is the ACME protocol a vanity project unique to Let's Encrypt? I manage several dozen certificates; I was very pleased when StartSSL offered an automated API to work with. Despite their flaws, they offered EV certs, wildcards, and automated one-shots, and it was very convenient. I'd gladly pay for this functionalit…

I'm the founder of SSLMate, which resells Comodo and GeoTrust certs with an automated, ACME-like API: https://sslmate.com

Our API predates ACME, but we'll most likely be implementing ACME once it's finalized.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#140

Earlier quoted context omitted.

I am having a really hard time following this argument. The CA isn't vouching for the content of your HTTPS requests.

No, the only thing the CA vouches for is that the other party is who they claim to be, which 99% of the time doesn't matter because I don't trust who they claim to be any more than I trust someone impersonating who they claim to be.

I'm still lost. What do you think it is that Comodo is vouching for with Hacker News?
Post reply on HN