Live data from Hacker News

DigiCert Statement on Trustico Certificate Revocation

digicert.com

21–30 of 76 posts

Re: DigiCert Statement on Trustico Certificate Revocation

#21
post #13

Apparently they had a web front end where customers could request private keys ... https://twitter.com/GossiTheDog/status/968834765888589825

Had? Have. https://www.trustico.com.au/ssltools/create/csr-pem/create-a... Generated server-side. http://termbin.com/eu4c

Yeah, that's actually surprisingly common, I remember working with a few before that did it. StartSSL and a Comodo reseller of some sort I think.

I'm done with these companies, Let's Encrypt seems to be the only people doing it right.

Re: DigiCert Statement on Trustico Certificate Revocation

#23
post #15

Earlier quoted context omitted.

> How is this not related to "the big distrust"? Unreal. If you mean the Symantec distrust - it's financially related but not technically related. In particular, it looks like Trustico ended their business agreement with Symantec (over the Symantec distrust) and signed a new contract with Comodo to resell Comodo certs instead. They wanted to move all their customers to the Comodo certs, and asked Digicert, the new ow…

Thank you for your explanation. I remember part of the Symantec problem was the uncontrolled resellers practices. Isn't this just some more dust under the rag coming out now?

Probably. In some amount of fairness, Trustico's stated motivation was that they didn't feel like they trusted Symantec (reasonable!) and the same people were involved with the move to Digicert (which I think is correct, some employees moved but technical oversight should have moved to the more organizationally-competent Digicert team) and the same problems were likely to happen again (I think Digicert is generally good at being a competent CA, but it's not unreasonable for them to decide the risk is too high if some of the same people were around).

They also state in the MDSP thread, "We were also a victim whereby Symantec mis-issued SSL Certificates owned by us, subsequently we were asked to keep the matter quiet, under a confidentially notice."

Re: DigiCert Statement on Trustico Certificate Revocation

#24
post #15

Earlier quoted context omitted.

Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.

> How is this not related to "the big distrust"? Unreal. If you mean the Symantec distrust - it's financially related but not technically related. In particular, it looks like Trustico ended their business agreement with Symantec (over the Symantec distrust) and signed a new contract with Comodo to resell Comodo certs instead. They wanted to move all their customers to the Comodo certs, and asked Digicert, the new ow…

This is all kinds of crazy at the same time.

Why would Trustico want to revoke certificates under the previous root anyway? Why not just start issuing certificates under the new, and just skip the part about broadcasting their little secret to the world?

Re: DigiCert Statement on Trustico Certificate Revocation

#25
post #18

I recently learned in my security class that certificates are the way by which domains are publicly identified. But I don’t understand why there hasn’t been any alternatives besides trusting these companies to issue certificates...

It would be really hard to keep everyone's browsers/operating systems updated with a list of certificates as they're generated and renewed.

You pretty much have to concentrate it down to a small subset of trusted certificate authorities to sign your certificate.

Also, it should be a way to verify that random people aren't able to get certificates on behalf of a domain they don't own (there's nothing stopping me from generating a cert for google.com - but it should be impossible for me to get it trusted by your browser).

Re: DigiCert Statement on Trustico Certificate Revocation

#28

The situation is unfolding in this Mozilla security policy mailing list thread: https://groups.google.com/forum/m/#!topic/mozilla.dev.securi...

I hope it's not overly pedantic to point out that what you linked to is not a CAB forum thread. That's a thread on the Mozilla security policy list, which many root programs and CAs make use of for disclosure and discussion.

CAB forum has its own lists elsewhere. A relevant difference is that CAB forum discusses creating and modifying policy but is not involved in enforcement. The root programs typically deal with enforcement.

Re: DigiCert Statement on Trustico Certificate Revocation

#29
post #28

The situation is unfolding in this Mozilla security policy mailing list thread: https://groups.google.com/forum/m/#!topic/mozilla.dev.securi...

I hope it's not overly pedantic to point out that what you linked to is not a CAB forum thread. That's a thread on the Mozilla security policy list, which many root programs and CAs make use of for disclosure and discussion. CAB forum has its own lists elsewhere. A relevant difference is that CAB forum discusses creating and modifying policy but is not involved in enforcement. The root programs typically deal with en…

I stand corrected, thank you.

Re: DigiCert Statement on Trustico Certificate Revocation

#30
The DV CA space is such a mess. I still wish DV certificate issuance was the responsibility of the domain registrar, with technical measures taken to prevent competing registrars from misissuance. This way, you don't need to play whack-a-mole around your certificates, just pick a reputable registrar when you buy your domain, avoid the need to "prove" you hold the domain (your registrar control panel is today already the sole security barrier protecting your domain), and avoid the possibility that a third party can play the impostor game. And it would bring some meaning back to the reputation of different TLDs and their various registrars.
Post reply on HN