A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
11–20 of 233 posts
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#12This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#13This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.
What is even the point of a web CA that isn't trusted by all of the major players? Is there one?
Why bake it into everybody else's Windows? If you make say a Brazil Government-only Windows which trusts this CA instead, I guarantee somebody crucial in Brazil will buy a 3rd party Windows laptop independently and it doesn't work with this CA's certificates and that ends up as Microsoft's problem to fix, so, easier to just have every Windows device trust the CA.
They'll have an assurance from the CA that it won't do this sort of crap, and that's enough, plausible deniability. Microsoft will say they take this "very seriously" and do nothing and it'll blow over. After all this stuff happened before and it'll happen again, and Windows will remain very popular.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#14Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#15Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#16Earlier quoted context omitted.
What is even the point of a web CA that isn't trusted by all of the major players? Is there one?
These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#17Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#18Can someone explain what could be done with that and by whom?
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#19The simple solution would be to have independent entities offer trust assertions about CAs and to allow users to consider multiple entities' views in their decision about whether to trust. It's surprising this doesn't exist yet when the attack vector is so clear.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#20This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good.