Live data from Hacker News

Comodo fails to check CAA records

mail-archive.com

31–40 of 71 posts

Re: Comodo fails to check CAA records

#31

Wikipedia has a nice list of previous Comodo malfeasance: https://en.wikipedia.org/wiki/Comodo_Group#Controversies Highlights include allowing fraudulent certs to be issued for Google, Yahoo, and Mozilla; working with a malware company; and trademark shenanigans with Let's Encrypt.

>working with a malware company Why is this a bad thing? A cert says "Yes, person x REALLY IS person x, and I can prove it mathematically." It doesn't say "Person x is trustworthy enough for me to vouch for them."

Who do you imagine they verified was Person X? More on the malware cert issuance: https://blogs.msmvps.com/donna/2009/05/18/microsoft-mvp-mike...

For malware concerns there's also Comodo's relationship with PrivDog. I'm not clear on whether PrivDog is deliberate malware or just incompetent insecure software.

Re: Comodo fails to check CAA records

#32

Wikipedia has a nice list of previous Comodo malfeasance: https://en.wikipedia.org/wiki/Comodo_Group#Controversies Highlights include allowing fraudulent certs to be issued for Google, Yahoo, and Mozilla; working with a malware company; and trademark shenanigans with Let's Encrypt.

In this particular case it's more likely negligence.

I can easily see how a missing integration test, and a few code changes later, the feature gets broken and nobody notices it. It doesn't prevent any normal codepath from executing properly.

Re: Comodo fails to check CAA records

#33

Earlier quoted context omitted.

How do you know they lied? What if they implemented it but simply did not flip the switch?

'Lie' is indeed a strong term, informally suggesting an intent to deceive. Personally, I would suspect negligence and incompetence rather than deceit, but negligence is a serious matter here.

Given the general crappiness of the CA industry, my first instinct is to say they willfully said "yeah we support it" without actually doing it first, knowing that it wasn't actually done.

Re: Comodo fails to check CAA records

#34
If you're not already familiar with his work, you should know that Hanno Böck is a machine, and someone worth following. If there's some mistake you can make with the web PKI that is so stupid nobody would ever bother to check for it, rest assured that Hanno will eventually check.

Re: Comodo fails to check CAA records

#35

Comodo is communicating actively in the bug, in the email discussion, and proactively CC'd the original reporter on the bug that was filed about this without being asked to do so. The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort. Applying that same prin…

I would bet money (maybe not a lot of money, but money) that the only outcome of this is that Comodo ends up within a month being the CA that most reliably checks CAA records. It would be shocking if Google penalized them for this.

As you say, that's based in part on how they handle it.

Re: Comodo fails to check CAA records

#36
post #34

If you're not already familiar with his work, you should know that Hanno Böck is a machine, and someone worth following. If there's some mistake you can make with the web PKI that is so stupid nobody would ever bother to check for it, rest assured that Hanno will eventually check.

Couldn't agree more, this (among others) was brilliant: https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-w...

Re: Comodo fails to check CAA records

#37

Comodo is communicating actively in the bug, in the email discussion, and proactively CC'd the original reporter on the bug that was filed about this without being asked to do so. The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort. Applying that same prin…

This reminds me of a parable:

An employee at a big company makes a mistake that costs the company $500,000. The client is livid, and demands he be fired. The owner's response? "Why would I fire him? I just spent half a million dollars on training!"

Re: Comodo fails to check CAA records

#38
post #4

maybe time to revoke Comodo's CA authority. Similar to what has happened before with Symantec (?).

Revocation for being three days late in implementing a new standard would be a massive overreaction. It would harm thousands of businesses in the process and would be extremely petty. Symantecs misdeeds are far worse than this.

Comodo doesn't have good security practices, it looks like, from my recent memory (confirmed with some google searches as well).

Re: Comodo fails to check CAA records

#39
post #37

Comodo is communicating actively in the bug, in the email discussion, and proactively CC'd the original reporter on the bug that was filed about this without being asked to do so. The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort. Applying that same prin…

This reminds me of a parable: An employee at a big company makes a mistake that costs the company $500,000. The client is livid, and demands he be fired. The owner's response? "Why would I fire him? I just spent half a million dollars on training!"

This tends to be over-used though. Unfortunately some employees would continue making $500,000 mistakes and never learning. It really depends on the employee's attitude and response to the incident, as well as the circumstances of the incident.

Re: Comodo fails to check CAA records

#40
post #37

Earlier quoted context omitted.

This reminds me of a parable: An employee at a big company makes a mistake that costs the company $500,000. The client is livid, and demands he be fired. The owner's response? "Why would I fire him? I just spent half a million dollars on training!"

This tends to be over-used though. Unfortunately some employees would continue making $500,000 mistakes and never learning. It really depends on the employee's attitude and response to the incident, as well as the circumstances of the incident.

It depends also on the employer's attitude and response to the incident. If the employee behaves perfectly and writes an impeccable post-mortem and is then fired "at the request of a client", that's on the employer, not the employee.
Post reply on HN