Live data from Hacker News

Bug 1758773: MITM in Russia

bugzilla.mozilla.org

1–10 of 18 posts

Re: Bug 1758773: MITM in Russia

#2
In the comment's zip attachment you can have a look at the certificate.

    Subject Name
    C (Country): RU
    O (Organisation): The Ministry of Digital Development and Communications
    CN (Common Name): Russian Trusted Root CA

    Issuer Name
    C (Country): RU
    O (Organisation): The Ministry of Digital Development and Communications
    CN (Common Name): Russian Trusted Root CA

    Issued Certificate
    Version: 3
    Serial Number: 10 00
    Not Valid Before: 2022-03-01
    Not Valid After: 2032-02-27
    Certificate Fingerprints
    SHA1: 8F F9 15 CC AB 7B C1 6F 8C 5C 80 99 D5 3E 0E 11 5B 3A EC 2F
    MD5: 7F BB 1F BB D1 29 47 E7 28 DC BF A4 56 8C 64 CD

Re: Bug 1758773: MITM in Russia

#3

In the comment's zip attachment you can have a look at the certificate. Subject Name C (Country): RU O (Organisation): The Ministry of Digital Development and Communications CN (Common Name): Russian Trusted Root CA Issuer Name C (Country): RU O (Organisation): The Ministry of Digital Development and Communications CN (Common Name): Russian Trusted Root CA Issued Certificate Version: 3 Serial Number: 10 00 Not Valid…

Also available on crt.sh: https://crt.sh/?id=6316640888 (from comment #7)

Re: Bug 1758773: MITM in Russia

#5
Seemingly they did not prepare early enough like the French [1] at the time. IMHO the whole cert trust chain is broken. Is there actually a services that serves cert fingerprints seen from another place in the world that can help detect a MITM?

[1] https://www.mozilla.org/en-US/security/advisories/mfsa2013-1...

Re: Bug 1758773: MITM in Russia

#6
How is this a bug in Mozilla? This seems to be about some email the Russian government has sent, and CA certificates.

If the certificate is being misused, I think it should be revoked by the authority who approved it.

Re: Bug 1758773: MITM in Russia

#7
post #6

How is this a bug in Mozilla? This seems to be about some email the Russian government has sent, and CA certificates. If the certificate is being misused, I think it should be revoked by the authority who approved it.

> If the certificate is being misused, I think it should be revoked by the authority who approved it.

That's the problem. There is no "authority who approved it", beyond the Russian government agency that created the certificate. The certificate is self-signed, and users are being asked to install it manually.

Re: Bug 1758773: MITM in Russia

#9
post #5

Seemingly they did not prepare early enough like the French [1] at the time. IMHO the whole cert trust chain is broken. Is there actually a services that serves cert fingerprints seen from another place in the world that can help detect a MITM? [1] https://www.mozilla.org/en-US/security/advisories/mfsa2013-1...

https://notary.icsi.berkeley.edu/

Re: Bug 1758773: MITM in Russia

#10
post #5

Seemingly they did not prepare early enough like the French [1] at the time. IMHO the whole cert trust chain is broken. Is there actually a services that serves cert fingerprints seen from another place in the world that can help detect a MITM? [1] https://www.mozilla.org/en-US/security/advisories/mfsa2013-1...

https://notary.icsi.berkeley.edu/

>Last updated: Thursday, 26. July 2018 03:21 PDT
Post reply on HN