Live data from Hacker News

The Power to Revoke Lies with the Certificate Authority

scotthelme.co.uk

21–30 of 89 posts

Re: The Power to Revoke Lies with the Certificate Authority

#22
post #5

Earlier quoted context omitted.

Yeah but I thought EV certificates involved phone calls, manual checks of the website, some basic security compliance... All the kind of manual paperwork & background checks that the standard certificate would not do.

right. and he passed the checks because his perfectly legitimate company is also called stripe inc and is also in the US, just in a different state. now stripe could take this up with the courts about how ian is confusing consumers and so forth, and they would win. but they didn't - they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not…

they went straight to the CAs

Is there any evidence that Stripe had anything to do with this?

Re: The Power to Revoke Lies with the Certificate Authority

#23
Here in the UK there is another problem with EV certs, there is no way of registering a "trading name" or "doing business as (DBA) name" against a company so you can only have an EV cert issues against your actual registered business name. If that is different from your trading name and what you use as your domain name then they are less than worthless. For example, if the company is "Widgets of London Limited" but trade online as "Widgets Online" with the domain "widgetsonline.com" they cant get an EV cert with "Widgets Online" as the name - even if they own the registered trademark of it.

Re: The Power to Revoke Lies with the Certificate Authority

#24
post #19

The idea behind EV's (to tie domain ownership to real-world legal entities) is sound, it's just that the implementation is poor. If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct respon…

But how would that help? Both Stripes would have a valid first class identity with valid keys. How are clients supposed to then check?

Re: The Power to Revoke Lies with the Certificate Authority

#25
There are several points in this post but the bulk of it is, I feel, one of those classic fallacies that journalists or security hobbyists often engage in:

"I found what looks like a flaw in a system but I didn't try to exploit it for real, look how clever I am"

So his mate registered a company with the same name as another company and got an EV cert. Well done. Everyone knew that was possible already, at least everyone who has gone through the process. It doesn't matter much:

1. Ian wasn't actually a phisher or criminal. If he had been, and had used that EV cert to phish Stripe customers, he'd have been reported to the police using the details from the CA and possibly prosecuted. Bear in mind he had to register a company in the USA, not Kazakhstan.

2. Therefore in reality it is very rare for phishers to use EV SSL certificates. Actually I've never seen it.

So is this a demo that the system is horribly flawed? I don't think so. It's rather similar to people who send 10 spams to some accounts they just registered themselves and claim they've found a way to beat a spam filter so the whole thing is useless ... well, no, you weren't actually a spammer so the filter did the right thing. You're testing a flaw you think sounds realistic but isn't. Another common case of this, someone who beats a DRM system on a game 6 months after it was released and then talks about how useless copy protection is, not realising that after 6 months almost all sales happened already so the system worked just fine from the developers perspective.

What about revocation? Is the CA exercising undue control here? Probably not. CAs have language in the contracts you agree to at the time about how you're not trying to misrepresent yourself as if you were someone else. Ian's argument that he registered a name that happens to be identical to a well known payment processor, but in another state, is technically correct, which is of course the best kind of correct. But the underlying purpose was clearly impersonation, which is a violation of the agreements and thus not only grounds for revocation, but to not do so would rather undermine the whole system - why should Ian get away with it when others do not?

If stripe.ian.sh had been an actual operating company that happened to have experienced an unfortunate naming conflict with the other Stripe, I bet the CAs would not have revoked. They'd have found some reasonable solution - probably by letting the cert continue, on the grounds that no malicious behaviour was taking place in violation of the agreements. But it wasn't - it was just a dummy site.

Overall I don't understand Scott or Ian's point. Yes, legal names aren't globally unique. Did anyone think they were? Yes, Chrome's EV UI is rubbish and the big players other than Apple tend to have an institutional dislike of EV certs because of historical clumsy attempts at market segmentation pricing by CAs, that were totally unreasonable for companies with lots of servers. Yes, EV is imperfect.

The alternative though is paypal-customer-centerr.com ... which is better, how, exactly? It isn't.

If Scott Helme or Ian Carroll don't like how EV works today, why not go find actual criminal abusers and propose specific improvements that would stop them - perhaps making Chrome's address bar work more like Safari's. Otherwise this is just another blog pointing out security stuff that doesn't really matter.

Re: The Power to Revoke Lies with the Certificate Authority

#26

Here in the UK there is another problem with EV certs, there is no way of registering a "trading name" or "doing business as (DBA) name" against a company so you can only have an EV cert issues against your actual registered business name. If that is different from your trading name and what you use as your domain name then they are less than worthless. For example, if the company is "Widgets of London Limited" but t…

Seems like you can, by registering a DUNS number, e.g. "Trade and DBA names are verified directly with registration agency or through a verified third party database such as D&B, Bloomberg, or Hoovers." (https://support.comodo.com/index.php?/Knowledgebase/Article/...)

Re: The Power to Revoke Lies with the Certificate Authority

#27
post #20
post #16

I think it's fine that they revoked the cert because Ian's site looked exactly like Stripe. The point he made still stands though: That the EV is pretty much only lipstick.

By "site", are you referring to the actual site, or the EV indicator? Because the site itself doesn't look anything like Stripe's[1]. [1]: https://stripe.ian.sh/

The Tweet shows part of the site as identical to Stripe's: https://twitter.com/iangcarroll/status/940281927789146112

I think the current look was updated later.

Re: The Power to Revoke Lies with the Certificate Authority

#28
post #9

Earlier quoted context omitted.

1: Look at the domain... https://www.paypal.com/.* https://www.stripe.com/* etc 2: PayPal/Stripe do have their one touch/sso stuff, if sign up with to that you'll have at least an indication if things go weird. Otherwise you are right. It's a problem but it's a problem with the web, not specifically any payment processors which are all honestly doing anything they can to make these issues a non-issue.

Looks at the domain can be deceiving because of IDN homograph attacks.

IDN homograph attack should not be an issue in your address bar - unicode letter trickery e.g. pаypal.com with a cyrillic а should be shown as xn--pypal-4ve.com ; it's something that can be solved and is being solved on the UI level.

Re: The Power to Revoke Lies with the Certificate Authority

#30
post #19

The idea behind EV's (to tie domain ownership to real-world legal entities) is sound, it's just that the implementation is poor. If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct respon…

But how would that help? Both Stripes would have a valid first class identity with valid keys. How are clients supposed to then check?

At least it could allow automating retrieving public information of the actual entity by whatever system checks the certification. Now, how to interact with the user to improve cognisance of the entity considered based on the newly available data is another problem.
Post reply on HN