Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

11–20 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#12

This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.

Also being issued on a major US holiday- when many are on PTO- does not help with the look.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#13
post #7

This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$.

Why bake it into everybody else's Windows? If you make say a Brazil Government-only Windows which trusts this CA instead, I guarantee somebody crucial in Brazil will buy a 3rd party Windows laptop independently and it doesn't work with this CA's certificates and that ends up as Microsoft's problem to fix, so, easier to just have every Windows device trust the CA.

They'll have an assurance from the CA that it won't do this sort of crap, and that's enough, plausible deniability. Microsoft will say they take this "very seriously" and do nothing and it'll blow over. After all this stuff happened before and it'll happen again, and Windows will remain very popular.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#15
post #6

Earlier quoted context omitted.

does that matter?

Yes; malice is indefensible no matter the circumstances, mistakes may be defensible under certain circumstances or with certain responses by the mistakee.

as a brazilian i’m not sure if I’d prefer it to be malice or incompetence

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#16
post #7

Earlier quoted context omitted.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

Windows is less popular every year.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#17
The simple solution would be to have independent entities offer trust assertions about CAs and to allow users to consider multiple entities' views in their decision about whether to trust. It's surprising this doesn't exist yet when the attack vector is so clear.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#18

Can someone explain what could be done with that and by whom?

Microsoft appears to have arranged with the government of Brazil for one of their national CAs to have the ability to mint arbitrary certificates. Only Microsoft's own WebPKI software cares; Chrome, Safari, and Firefox don't trust this CA.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#19
post #17

The simple solution would be to have independent entities offer trust assertions about CAs and to allow users to consider multiple entities' views in their decision about whether to trust. It's surprising this doesn't exist yet when the attack vector is so clear.

This is something more akin to a client software bug than a WebPKI issue. Any alternative PKI scheme you could come up with would still be subject to Microsoft cutting deals.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#20
ICP-Brasil officially stopped emitting public-facing SSL/TLS certificates in October: https://www.gov.br/iti/pt-br/assuntos/noticias/indice-de-not...

This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good.

Post reply on HN