Live data from Hacker News

Comodo fails to check CAA records

mail-archive.com

21–30 of 71 posts

Re: Comodo fails to check CAA records

#21
post #4

maybe time to revoke Comodo's CA authority. Similar to what has happened before with Symantec (?).

Revocation for being three days late in implementing a new standard would be a massive overreaction. It would harm thousands of businesses in the process and would be extremely petty. Symantecs misdeeds are far worse than this.

Revocation can be done only for new certs. It's time to throw a CA to the dogs once in a while pour encourage les autres.

Re: Comodo fails to check CAA records

#22

Earlier quoted context omitted.

Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.

That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.

Karunamon et. al. are not saying your point is wrong; they are saying it is irrelevant, and if their facts are correct then they are right.

Re: Comodo fails to check CAA records

#23

Earlier quoted context omitted.

Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...

Ah, so they are three days late. That doesn't sound too serious.

I wonder about what else is Comodo being "not too serious" while they promise to be "super serious" about them in their marketing campaigns?

Re: Comodo fails to check CAA records

#24

Earlier quoted context omitted.

Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.

That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.

It's not about them being late these 3 days. It's about them lying about having already implemented this months ago.

Re: Comodo fails to check CAA records

#25
Wikipedia has a nice list of previous Comodo malfeasance: https://en.wikipedia.org/wiki/Comodo_Group#Controversies

Highlights include allowing fraudulent certs to be issued for Google, Yahoo, and Mozilla; working with a malware company; and trademark shenanigans with Let's Encrypt.

Re: Comodo fails to check CAA records

#26
post #10

Worth noting that the rule they broke has only been in effect for three days ( https://cabforum.org/2017/03/08/ballot-187-make-caa-checking... ). This might cause the CAB to go a bit easier on them.

They also voted "yes" to the proposal and had 6 months to implement it.

Exactly. For some contrast: I use tinydns, which doesn't natively support CAA records. But I wanted them so I read the CAA spec and wrote a little tool to add support for these records using the generic record format. And I'm not even a programmer! (I can write a little code, nothing serious, and nobody would hire me for it.)

And yet with all of Comodo's resources, they couldn't get this done? I can't take them seriously.

Re: Comodo fails to check CAA records

#27
post #24

Earlier quoted context omitted.

That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.

It's not about them being late these 3 days. It's about them lying about having already implemented this months ago .

How do you know they lied? What if they implemented it but simply did not flip the switch?

Re: Comodo fails to check CAA records

#28

Wikipedia has a nice list of previous Comodo malfeasance: https://en.wikipedia.org/wiki/Comodo_Group#Controversies Highlights include allowing fraudulent certs to be issued for Google, Yahoo, and Mozilla; working with a malware company; and trademark shenanigans with Let's Encrypt.

>working with a malware company

Why is this a bad thing? A cert says "Yes, person x REALLY IS person x, and I can prove it mathematically." It doesn't say "Person x is trustworthy enough for me to vouch for them."

Re: Comodo fails to check CAA records

#29
Comodo is communicating actively in the bug, in the email discussion, and proactively CC'd the original reporter on the bug that was filed about this without being asked to do so.

The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort.

Applying that same principle to CA operations, why on earth should Comodo be "fired" as a CA for this? They're actively working to solve it, they're responsive, and the agreements they operate under will compel a post-mortem into existence if only to meet the terms of their next CA audit.

If, after investigation, they are found to be willfully violating policy, knowingly lying about CAA support, fail to produce an acceptable post-mortem, and/or fail their next CA audit, then of course they should be at risk of direct sanctions - not just a verbal reprimand.

So if your initial response to this issue is "Comodo should be fired", remember that in Operations culture that specific response "X should be fired" is a harmful response to a zero-day report of an incident, and many Operations teams would fire anyone who called for a firing in response to a fresh incident, in order to protect others from that harmful posture.

Re: Comodo fails to check CAA records

#30
post #24

Earlier quoted context omitted.

It's not about them being late these 3 days. It's about them lying about having already implemented this months ago .

How do you know they lied? What if they implemented it but simply did not flip the switch?

'Lie' is indeed a strong term, informally suggesting an intent to deceive. Personally, I would suspect negligence and incompetence rather than deceit, but negligence is a serious matter here.
Post reply on HN