DigiCert Statement on Trustico Certificate Revocation
11–20 of 76 posts
Re: DigiCert Statement on Trustico Certificate Revocation
#12Earlier quoted context omitted.
Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.
If they operate as any other CA does, there's no reason to assume that they would have had any way to have the private keys which would only ever be on customer systems. This implies that Trustico was sent the keys (or recieved them somehow) from a third party who had compromised them. 20k certs implies a tremendous number of clients; seems tome it's more likely one of Trustico's intermediate CA certs got compromised…
For example, consider this page: https://www.trustico.com.au/ssltools/create/csr-pem/create-a...
The best part - it doesn't even use browser crypto. The private key is generated server-side and then rendered in the server response.
Private key generation on the reseller-side - what can go wrong.
Re: DigiCert Statement on Trustico Certificate Revocation
#13Apparently they had a web front end where customers could request private keys ... https://twitter.com/GossiTheDog/status/968834765888589825
https://www.trustico.com.au/ssltools/create/csr-pem/create-a...
Generated server-side.
Re: DigiCert Statement on Trustico Certificate Revocation
#14Earlier quoted context omitted.
If they operate as any other CA does, there's no reason to assume that they would have had any way to have the private keys which would only ever be on customer systems. This implies that Trustico was sent the keys (or recieved them somehow) from a third party who had compromised them. 20k certs implies a tremendous number of clients; seems tome it's more likely one of Trustico's intermediate CA certs got compromised…
Well, Trustico is a reseller. There's very little to stop them doing anything they want, since they are not subject to CABF regulations. For example, consider this page: https://www.trustico.com.au/ssltools/create/csr-pem/create-a... The best part - it doesn't even use browser crypto. The private key is generated server-side and then rendered in the server response. Private key generation on the reseller-side - what…
Re: DigiCert Statement on Trustico Certificate Revocation
#15Had to read it like 3 times before I could process. Unreal.
Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.
If you mean the Symantec distrust - it's financially related but not technically related.
In particular, it looks like Trustico ended their business agreement with Symantec (over the Symantec distrust) and signed a new contract with Comodo to resell Comodo certs instead. They wanted to move all their customers to the Comodo certs, and asked Digicert, the new owners of the old Symantec root, to issue revocations.
When Digicert said no, that's not how it works, they responded by sending over all of the private keys they had. The fact that they had those keys, and the fact that they sent them via email to Digicert, is entirely separate from any technical problem that Symantec or Digicert may have had.
Re: DigiCert Statement on Trustico Certificate Revocation
#16Earlier quoted context omitted.
Well, Trustico is a reseller. There's very little to stop them doing anything they want, since they are not subject to CABF regulations. For example, consider this page: https://www.trustico.com.au/ssltools/create/csr-pem/create-a... The best part - it doesn't even use browser crypto. The private key is generated server-side and then rendered in the server response. Private key generation on the reseller-side - what…
They are still effectively subject to the CA/B rules. The issuer of the certs is subject to the rules, and they must ensure compliance of any companies they delegate to.
However, even if we assume Trustico was an authorized party, the keys became compromised the moment they were disclosed to DigiCert unless the terms their users agreed to included DigiCert as an authorized party. Even if they were you could make an argument that those keys were compromised due to the fact that they were literally sent via email, unless they were properly encrypted and what not.
Re: DigiCert Statement on Trustico Certificate Revocation
#17Re: DigiCert Statement on Trustico Certificate Revocation
#18Re: DigiCert Statement on Trustico Certificate Revocation
#19Re: DigiCert Statement on Trustico Certificate Revocation
#20Earlier quoted context omitted.
Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.
> How is this not related to "the big distrust"? Unreal. If you mean the Symantec distrust - it's financially related but not technically related. In particular, it looks like Trustico ended their business agreement with Symantec (over the Symantec distrust) and signed a new contract with Comodo to resell Comodo certs instead. They wanted to move all their customers to the Comodo certs, and asked Digicert, the new ow…
I remember part of the Symantec problem was the uncontrolled resellers practices. Isn't this just some more dust under the rag coming out now?