Live data from Hacker News

Mozilla wants CAs to revoke 30 random certificates per year

groups.google.com

11–20 of 36 posts

Re: Mozilla wants CAs to revoke 30 random certificates per year

#11

Earlier quoted context omitted.

To put things into perspective, the people behind the browser with The reality is the CAs could tell Mozilla to go pound sand and they would have no recourse. Is there not a governing body for certificate policies with voting members? CA trust should be handled at the OS vendor level. Mozilla having its own trust anchors is a relic of the past. If CAs refuse to comply, they at worst inconvenience 2.5% of their custom…

>CA trust should be handled at the OS vendor level. Who's the "vendor" for Linux? IBM? The outcome of this idea is Google & Microsoft can MITM all internet traffic.

> The outcome of this idea is Google & Microsoft can MITM all internet traffic.

Google, MS, and Apple already handle their own CA trust. So this conspiracy theory would already be true.

Re: Mozilla wants CAs to revoke 30 random certificates per year

#15
post #4

That is a pretty breathtaking example of ivory tower thinking if there ever was one. I really just don't know what else I can say about that kind of proposal.

To put things into perspective, the people behind the browser with The reality is the CAs could tell Mozilla to go pound sand and they would have no recourse. Is there not a governing body for certificate policies with voting members? CA trust should be handled at the OS vendor level. Mozilla having its own trust anchors is a relic of the past. If CAs refuse to comply, they at worst inconvenience 2.5% of their custom…

Google Chrome also takes a hard line when it comes to revocation requirements, and Apple wants to limit certificate lifetimes to 45 days. Although neither have stated a position on random revocations, they are directionally aligned with Mozilla and you will be disappointed if you expect either of them to prioritize server operator convenience over the security of their users.

As for Microsoft, they are simply asleep at the wheel, trusting terrible CAs that do things like misissue a google.com certificate https://bugzilla.mozilla.org/show_bug.cgi?id=1934361>.

Re: Mozilla wants CAs to revoke 30 random certificates per year

#16
post #5

I think Roman Fischer in the thread has it right, 30 certs is a single drop of water the Atlantic. Like there's no wink wink necessary, at that scale it would be flatly irrational to do anything at all to handle being one of these revocations. We're taking about a roughly 0.00001% chance that it's you. Forget some dumb cert revocation logic I would play Russian Roulette with those odds. But on the flip side those 30…

1 in 100k chance of taking down Amazon for say a day means the expected cost to them would be 140k per year based on their daily revenue. So in fact it's worth them hiring someone full time permanently to handle these revocations...

Re: Mozilla wants CAs to revoke 30 random certificates per year

#17

Why don’t they revoke the certificate for a special-use domain, like example.com. As opposed to 30-random entities. https://en.m.wikipedia.org/wiki/Special-use_domain_name

The goal is to ensure not just that the CA is capable of performing the revocation, but that the CA's customers are capable of accepting it and won't demand the timeline be extended. (As they routinely do today.)

Re: Mozilla wants CAs to revoke 30 random certificates per year

#18
post #5

I think Roman Fischer in the thread has it right, 30 certs is a single drop of water the Atlantic. Like there's no wink wink necessary, at that scale it would be flatly irrational to do anything at all to handle being one of these revocations. We're taking about a roughly 0.00001% chance that it's you. Forget some dumb cert revocation logic I would play Russian Roulette with those odds. But on the flip side those 30…

1 in 100k chance of taking down Amazon for say a day means the expected cost to them would be 140k per year based on their daily revenue. So in fact it's worth them hiring someone full time permanently to handle these revocations...

Responding to revocations can be automated, and mature organizations like Amazon are presumably already doing that because revocations can already happen unexpectedly for reasons outside their control.

Re: Mozilla wants CAs to revoke 30 random certificates per year

#19

Earlier quoted context omitted.

To put things into perspective, the people behind the browser with The reality is the CAs could tell Mozilla to go pound sand and they would have no recourse. Is there not a governing body for certificate policies with voting members? CA trust should be handled at the OS vendor level. Mozilla having its own trust anchors is a relic of the past. If CAs refuse to comply, they at worst inconvenience 2.5% of their custom…

>CA trust should be handled at the OS vendor level. Who's the "vendor" for Linux? IBM? The outcome of this idea is Google & Microsoft can MITM all internet traffic.

> Who's the "vendor" for Linux? IBM?

There are countless companies and groups (but only a handful that serve the vast majority of users) releasing a version of Linux bundled with a GNU userland and other open source niceties, all designed to work together as a system. These are colloquially called "Linux distributions".

Re: Mozilla wants CAs to revoke 30 random certificates per year

#20
post #12

This is classic "we don't have a purpose so let's cause problems" thinking. WTF!!

It's not even the most insane suggestion in the thread. That would be the proposal to require ACME for all certificates. So all your appliances with manual cert installation and devices without direct connection to the internet would break.
Post reply on HN