Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

161–170 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#161
post #128

Earlier quoted context omitted.

The people saying this is "generous" are making largely irrational arguments. What Mozilla is proposing is the worst case for incumbent CAs.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

> it's annoying for customers, but they just have to subscribe to a new CA and install the new cert

Well I would be a little more embarrassed than that, because Wosign/Starcom were the only ones offering free SSL certificates for international domain names.

So there's no way I would pay for SSL certificates for my various personal projects and websites, but then I just couldn't get valid certificates for them anymore. Let's Encrypt might start offering them in the future, but nothing's official yet.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#162
post #60
post #50

Earlier quoted context omitted.

Given WoSign's history of backdating SHA-1 certificates in violation of Mozilla's rules, I wouldn't be too surprised if they reuse that practice to get around the 1 year ban, at which point Mozilla will have to consider permanently distrusting them.

They've already considered it and are including this in their proposal: > WoSign/StartCom could back-date certificates to get around this restriction. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.

Would they do this out of spite? StartCom is essentially done for and has little to lose, so out of bitterness they could try to turn their customers against the browser vendors.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#163
post #128

Earlier quoted context omitted.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…

> If I ran a CA, I'd be much more nervous about this than I would be about them zapping the CA and all its customers.

Exactly. If they insta-revoked the whole CA, it'd hurt a pile of customers (many of which might decide that HTTPS isn't worth the hassle for them). And bigger CAs would say "eh, they can't do that to us, they'd break half the web".

Showing that they're willing to say "no new certs from this CA" means they can use that sanction against any arbitrarily large and popular CA.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#164
post #141

It's a shame it sounds like there are no legal avenues for penalising the individuals behind this. Actions like this ought to be criminal. In the end, if the only penalties are directed at corporations involved it isn't much a of disincentive to state actors or others with sufficient resources who want to game the system.

Individuals? This sounds like a systemic organizational issue. I'm sure we can drum up a few scapegoats, but I'm not sure if that'll be terribly effective in fixing the incentives.

Putting everyone involved out of a job and destroying whatever investments in the company they may have had, on the other hand, puts pressure on everyone involved to not fuck up next time.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#165
post #65

Earlier quoted context omitted.

Isn't that only E&Y Hong Kong, though? Really at this point I don't know why anybody in China, or any country known for its corruption, should be accepted as auditors.

You're painting 1 billion people with a rather broad brush.

No, it is pretty well established that countries have corruption problems, and cultural attitudes can be at variance to what you would expect. Many practices we would find outragously corrupt are common in China, with no recourse through the legal system.

https://www.transparency.org/country/#CHN

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#166

Earlier quoted context omitted.

> The "logic" behind PKI dictates that it's a third party identifying my bank to me Not true. The third party is an operational detail to scale, there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? You're suggesting that you don't trust your bank's opinion on what websites belong to them, but do trust some third party's? Even if this made any sense, the thir…

there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…

> Connecting to TLS to news.ycombinator.com is nice in that I know nobody has read or altered the message in transit. The fact that a third party vouches that news.ycombinator.com is who they say they are doesn't add anything for me, because I don't trust news.ycombinator.com any more than I would trust somebody impersonating news.ycombinator.com. The CA in this situation simply complicates things and adds nothing for me.

You don't know that the message isn't read or altered in transit unless you know that your TLS connection is to the real news.ycombinator.com.

ISPs have been running transparent HTTP proxies to inject ads and other nonsense into your content. It'd be trivial for them to run a transparent HTTPS proxy to do the same - aside from the little detail that your browser would try and fail to verify the certificates provided by said proxy were vouched for by a CA.

I don't consider this is a "largely-hypothetical" attack. ISPs have been doing it for a few extra pennies of ad revenue.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#167
post #18

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…

CAs need irreproachable reputations, anything less is absurd, like trusting your bank manager even though you know they have a gambling problem and owe money to Fat Tony. Having sympathy for their commercial corcerns is absurd.

The better solution would be to alert on all of their certs as being 'low trust'. A first step towards explicit trust belief, where reputations build slowly over time and can be severly damaged by bad behavior.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#168

Earlier quoted context omitted.

And here's the technical detail of how we do it: https://blog.cloudflare.com/tls-certificate-optimization-tec... .

Is there actually an open source implementation of this though? I've looked, but never found one, though that was quite some time ago. Perhaps things have changed. This approach is beyond the ability of most to implement for themselves if they don't have support from their webserver for it.

A recent combination of Apache and OpenSSL has support for certificate switching based on key algorithm. You can serve an ECDSA+SHA2 certificate to clients that support ECDSA, and an RSA+SHA1 certificate to clients that don't. I'm pretty sure that all clients that reject SHA1 support ECDSA, so this should work.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#170
post #39

While most of the doc focused on StartCom/WoSign, I thought this bit at the end was interesting: > no longer accept audits carried out by Ernst & Young (Hong Kong). To reject audits from E&Y.... It makes me wonder about the transparency and trust we put in the auditors as being a key part of CA validation process.

Auditors and ratings agencies and their ilk are a fundamentally broken service in our society. On the one hand they have to make money and on the other they have to be honest. The two are simply not compatible, seemingly. Eg: ratings agencies happily giving top tier ratings to mortgages back in pre 2008.

Completely Agree!

When you think down this path, its why Certificate Transparency Logs make even more sense -- Yes, its still ideal that a CA operates in a "good" way, but using the Cert Logs you know everything they have signed, so a rouge actor has a limited ability to sign something they shouldn't, and as seen by Mozilla's document, they used the Cert Transparency logs as part of their evidence.

Post reply on HN