Live data from Hacker News

DigiCert Statement on Trustico Certificate Revocation

digicert.com

1–10 of 76 posts

Re: DigiCert Statement on Trustico Certificate Revocation

#7
post #2

Had to read it like 3 times before I could process. Unreal.

Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.

If they operate as any other CA does, there's no reason to assume that they would have had any way to have the private keys which would only ever be on customer systems.

This implies that Trustico was sent the keys (or recieved them somehow) from a third party who had compromised them.

20k certs implies a tremendous number of clients; seems tome it's more likely one of Trustico's intermediate CA certs got compromised and these 20k are newly issues ones against that compromised CA cert.

Re: DigiCert Statement on Trustico Certificate Revocation

#9

Earlier quoted context omitted.

Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.

If they operate as any other CA does, there's no reason to assume that they would have had any way to have the private keys which would only ever be on customer systems. This implies that Trustico was sent the keys (or recieved them somehow) from a third party who had compromised them. 20k certs implies a tremendous number of clients; seems tome it's more likely one of Trustico's intermediate CA certs got compromised…

They apparently have a “certificate wizard” that will generate the certificate and corresponding private key for you. Of course that’s practical for the end user (generating a CSR can be cumbersome), but obviously insecure.

They’re not the only party to do so either, e.g. DNSimple (which is otherwise a great company!) also provide APIs to have them generate and store certificates including private keys: https://developer.dnsimple.com/v2/certificates/#getCertifica...

Re: DigiCert Statement on Trustico Certificate Revocation

#10

Earlier quoted context omitted.

Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.

If they operate as any other CA does, there's no reason to assume that they would have had any way to have the private keys which would only ever be on customer systems. This implies that Trustico was sent the keys (or recieved them somehow) from a third party who had compromised them. 20k certs implies a tremendous number of clients; seems tome it's more likely one of Trustico's intermediate CA certs got compromised…

In the thread at https://groups.google.com/forum/m/#!topic/mozilla.dev.securi... is this tidbit:

> We have purchased thousands of certificates using Trustico as a reseller within the last years. Back in these days Trustico created CSR / Private Key pair within their online platform (Yes, you read it right - you can create CSR/Private Key on their webpage !!!) which was the default at this time and it is still possible to do so in their web interface.

Post reply on HN