Live data from Hacker News

Apple's response to the WoSign incidents

groups.google.com

11–20 of 39 posts

Re: Apple's response to the WoSign incidents

#11
post #6
post #2

Seems like a sensible response. I do wonder how they will know what certificates are currently signed by WoSign, as they stated that individual certificates will still be trusted somehow.

Apple will continue to trust existing certs from WoSign (provided they are CT logged). New certs will not be trusted. mac OS will make this decision by first looking at signatures. It will receive the "end-entity" certificate (a cert for a specific site, like example.com) and while checking the chain, will see that there is a signature from the "WoSign CA Free SSL Certificate G2 intermediate CA" certificate. It will…

> If the certificate is preexisting (presumably issued before 9/19/16) it will be trusted ONLY if the certificate is CT logged. It will know if this is the case by looking for an SCT belonging to that certificate. The SCT will either be embedded directly in the certificate, or provided with the certificate during the SSL handshake (this is known as "stapling").

I doubt they'll do it this way. WoSign has only been embedding SCTs for all certificates since July and I wouldn't count on many webservers implementing SCT stapling. I expect Apple to ship a whitelist of hashes of certs that should be trusted instead.

Re: Apple's response to the WoSign incidents

#12
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

I’m just curious, what standards did they violate other than circumventing SHA-1 deprecation?

Re: Apple's response to the WoSign incidents

#13
post #12
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

I’m just curious, what standards did they violate other than circumventing SHA-1 deprecation?

A number of issues can be found here[1]. Among other things, they allowed domain validation on unprivileged ports and issued certificates for "parent" domains when subscribers were able to validate control of a subdomain (i.e. you could get a certificate for github.com by controlling user.github.com).

[1]: https://wiki.mozilla.org/CA:WoSign_Issues

Re: Apple's response to the WoSign incidents

#14
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

For those who may not remember or may not have heard, QiHoo is the company behind the most popular scam browsers in the world: Qihoo 360 Secure. It was one of the most popular browsers in China with 28% of the market a few years ago. It used an IE logo colored green, force-uninstalled competing browsers by claiming they were unsafe, made uninstallation so difficult you'd often have to re-image the machine, breaks SSL, can expose user passwords, etc.

Remember, this is a "security" company.

It's rather fascinating: https://webdesign.tutsplus.com/articles/qihoo-360-secure-the...

Personally, I wouldn't trust anything this "security" company is connected with anywhere need my devices, software, or business.

Re: Apple's response to the WoSign incidents

#15
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

For those who may not remember or may not have heard, QiHoo is the company behind the most popular scam browsers in the world: Qihoo 360 Secure. It was one of the most popular browsers in China with 28% of the market a few years ago. It used an IE logo colored green, force-uninstalled competing browsers by claiming they were unsafe, made uninstallation so difficult you'd often have to re-image the machine, breaks SSL…

And yet, unless you go through the effort of removing every trusted CA from your browser, you implicitly trust them because Mozilla/Google/etc. do.

And thus why the CA system is broken in a nutshell.

Re: Apple's response to the WoSign incidents

#16
Sorry if this is obvious to others, but just to be clear ...

As it's widely reported that WoSign has taken over StartCom's infrastructure, this implies that StartCom StartSSL Free certificates going forward won't be trusted by Apple either, correct?

It also sounds a little strange to only call out the free certificates. Are they going to allow new paid OV/EV (and what they call 'IV') certificates to remain valid?

Re: Apple's response to the WoSign incidents

#17
post #7

That should serve as a clear warning to other certificate authorities. Behave or you will be ruined. For most CAs having either Apple, Mozilla, Microsoft or Google remove your root certificate will drive customers away to the point where you might as well close up shop.

nobody has been ruined just yet. and when i look at how sheepishly slow mozilla reacts my guess is nobody will ever really get thrown out of that club.

what they've done is clear. it's been misconduct as a ca. untrust them. done. fuck you.

Re: Apple's response to the WoSign incidents

#18
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

Ugh. September 19th is poor date to choose.

When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point.

But that was on ~26th September.

Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

Re: Apple's response to the WoSign incidents

#19
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

Ugh. September 19th is poor date to choose. When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point. But that was on ~26th September. Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

    When this came up, the first thing I did was generate wildcard certs for our StartCom domains
A vendor you used comes under scrutiny so your response is to double down on them? Did you have prepaid credits or something? It seems like that would have been a opportune time to migrate away from them since you'd have to redeploy certs anyways.

Re: Apple's response to the WoSign incidents

#20
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

Ugh. September 19th is poor date to choose. When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point. But that was on ~26th September. Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

That seems like an odd move, doubling down on the CA after news of them doing shady stuff? Why not take that opportunity to switch to something else like let's encrypt?
Post reply on HN