WoSign and StartCom: Mozilla’s proposed conclusion
141–150 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#142I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#143A 1-year time-out is insufficient to regain trust, IMO.
I would never let them return, absent some kind of additional (exculpatory) information)
They won't even admit to their behavior!
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#144If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.
Even after this disclosures, a fully informed, rational agent would still choose WoSign if their price and service were the best. This is because WoSign's behavior does not specifically endanger their customers. The SSL ecosystem relies on the trustworthiness of the certificate authorities. If one of them is compromised, the whole system is compromised, not just their customers. This cannot be solved by markets. Inst…
WoSign's behavior does not specifically endanger
their customers.
Or more precisely, problems such as issue N [1] endanger their customers, but endanger non-customers just as much.[1] https://wiki.mozilla.org/CA:WoSign_Issues#Issue_N:_Additiona...
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#145Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing certs (while still manually checking every cert request, at least for any OV&EV cert in my case). This entire WoSign acquisition is incredibly shady. Shortly after that some of the customer reps had chinese names, service quality declined and we got offered to…
What use case do you have for wildcards that you can't use Let's Encrypt or similar automated issuance? Just curious, as I've yet to hear a terribly compelling one...
- EV (green bar) certs are required to increase customer trust (it may be mostly snakeoil, but the CA system is heavily flawed and we are still forced to rely on it anyway)
- Applications where certs are used on other platforms than web servers (e.g. embedded devices, routers etc.) and 90-day renewals are not easy to implement in an automated way.
- Wildcard certs are mostly useful for convenience reasons, e.g. to easily secure a changing number of hosts within certain (sub)domains/zones (especially when they are only or mostly used in internal networks). I agree that the need for wildcard certs is greatly reduced with let's encrypt and acme.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#146Earlier quoted context omitted.
No, the only thing the CA vouches for is that the other party is who they claim to be, which 99% of the time doesn't matter because I don't trust who they claim to be any more than I trust someone impersonating who they claim to be.
I'm still lost. What do you think it is that Comodo is vouching for with Hacker News?
This is at least less wasteful of time and effort on everybody's part than Comodo verifying that a specific company or person was actually involved; again, I don't trust ycombinator any more than I trust someone impersonating ycombinator, so any 3rd party verification is kind of pointless to me.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#147A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…
"what does the punishment need to be to prevent others from seeing it, and thinking it's a risk worth taking?" is a better one.
For me, I think it should be permanently revoked.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#148I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?
When the story first broke, I manually untrusted WoSign's and StartCom's root certificates in OS X, instead of deleting them outright...at least I thought I did. I upgraded to macOS 10.12 Sierra this past weekend, and repeated the process. Except WoSign's certificates aren't there to begin with, though StartCom's still are. So perhaps Apple had dropped WoSign already? Would anyone else running 10.12 verify?
(Not sure if cached intermediate certificates get added to the keychain - maybe that's what you saw previously?)
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#149Earlier quoted context omitted.
And here's the technical detail of how we do it: https://blog.cloudflare.com/tls-certificate-optimization-tec... .
Is there actually an open source implementation of this though? I've looked, but never found one, though that was quite some time ago. Perhaps things have changed. This approach is beyond the ability of most to implement for themselves if they don't have support from their webserver for it.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#150Earlier quoted context omitted.
How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…
Yeah but the existing certs are still out there. While it's great that a company is being punished, this completely ignores the fact that we have no idea what they've signed, and short of laboriously checking the trust path of every single certificate you encounter there's no way to know if the cert you're looking at at any given moment came from them or not. And worse yet, the bigger problem is there's not a practic…
There's been some talk on mozilla.dev.security.policy about actively distrusting WoSign/StartCom-issued certificates for domains that have not been disclosed to CT as WoSign/StartCom subscribers (by baking the domain list into various browser binaries). That's probably the best option all around, though I'm not sure if it's going to happen (the report doesn't mention this).