Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

101–110 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#101
post #90

Earlier quoted context omitted.

You can totally ignore the red herring and focus on the first part. In the end I was just paraphrasing the comment I replied to. Rotations exist, specially in large organizations, or when there's shared responsibility. Now we're talking nonsense about "you said, he said", this conversation makes no sense. I am much less invested in this than you think.

> Rotations exist Straw man [1]. Nobody claimed otherwise. Rotation or always-on isn’t a substitute for being aware of your customers. Good culture permeate this throughout the organisation. Competent ones have someone at the top ensuring controls are followed. [1] https://en.m.wikipedia.org/wiki/Straw_man

Sorry, I lost the track.

Can you explain the point you made precisely, in the context of the original subject?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#102
post #43

Earlier quoted context omitted.

Also being issued on a major US holiday- when many are on PTO- does not help with the look.

During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.

My comment is not about how all work should stop during US holidays.

What I’m attempting to refer to, is that _if_ this was done with malicious intent, then maybe the hope was that doing it during a holiday would reduce response time or allow it to fly under the radar. Of course, as you say, just because it was a holiday does not inherently mean it’s malicious, it has plausible deniability.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#103
post #49

Earlier quoted context omitted.

what's the state's interest in having their CA built into windows?

So they can mitm their own employees without annoying TLS warnings.

To be clear, this is bog standard in all mega-corps now. They have a vendor product that provides HTTP Internet proxy, then they perform MitM to decrypt HTTPS traffic and re-sign/encrypt with in-house issued cert. Then, this cert is auto-trusted as part of all base OS installations. To be honest, how else can mega-corps spy on HTTPS traffic without this MitM tactic? I don't know any other way.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#104
post #36

Earlier quoted context omitted.

As a brazillian, I find this very unlikely. In 2013, when the same party was in power, SERPRO was tasked with replacing Microsoft in key aspects, such as government email (which was handled by Outlook Server at that time) and operating systems. The main reason was fear of espionage. So, in reality, we are more afraid of the US spying on us than random internet dissidents.

As a non Brazilian, sometimes when a government says a company is spying on its citizens, they mean that they want access, too, to the spying and censoring apparatus.

I see your point.

Maybe if I was in government I would think the same. Catch criminals before they act, stuff like that (I'm just being the devil's advocate here).

This is a dillema, and the worst kind. The kind citizens know nothing about, so the only possible way to talk about it is to speculate. I am, however, too old to speculate about these things anymore.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#105

Earlier quoted context omitted.

Do you actually understand what's going here?

As someone who doesn't understand what's actually going on: could someone ELI5?

CAs are in the business of being a trusted third party that, among other things, verifies the identity of things. In this case someone seems to have scammed/hacked/whatever the CA into issuing a certificate for google.com, which is clearly bogus. So the result is that we should not trust this CA anymore.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#106

Microsoft seems to be casual about trusting CAs, isn't transparent in their inclusion decisions, and their trust store is quite large. Any reasonable website would only use a certificate trusted by a quorum of browsers (especially Chrome), so the benefit of the extraneous CAs seems low. I'm not a Windows user, but I have to wonder if there's a way to use the Chrome trust store on Windows/Edge. I can't imagine trustin…

    > Microsoft seems to be casual about trusting CAs
Woah, that is a bold statement. Classic HN overreach. I am not here to shill for MSFT, but, in terms of OS sales to gov'ts, no one else has nearly the same level of experience. I am sure that MSFT carefully vets all CA additions.

Are you aware of the big hack on Netherlands govt-approved CA? Read about: DigiNotar. My point: That was a widely trusted CA that was hacked after the root CA cert was added to most browsers / OSes trust stores. So would you say that MSFT was "casual" about trusting DigiNotar root CA? How about Mozilla Firefox? I doubt it.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#107
post #28

Not clear (to me) in the original post -- was this done accidentally or intentionally?

The certificate was registered in CT, so a reasonable assumption would be that this was accidental, because it was guaranteed to be noticed and to generate drama that would threaten the capability they arranged, presumably at some significant expense.

What is CT here? Central Time? Connecticut? Maybe Certificate Transparency? I guess that last one might make the most sense. Abbreviations are hard.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#108
post #85

Tangentially related: The system is deeply flawed, which is something I realized fifteen years ago when I was put into a situation where I had to use online banking. (Had to being the nearest branch of any bank was an hour long flight away, though there was an ice road you could use in the winter.) One of my first questions of the bank was: who issued their certificate. They didn't have a clue what I was talking abou…

First, you don't tell us the location. Are we talking about a CA in Syria or Canada? It makes a big difference. Second, yeah, I'm sure banking regulators say nothing to commercial banks about using a reputable CA.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#109
post #43

Earlier quoted context omitted.

Also being issued on a major US holiday- when many are on PTO- does not help with the look.

During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.

[deleted]

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#110
post #43

Earlier quoted context omitted.

During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.

My comment is not about how all work should stop during US holidays. What I’m attempting to refer to, is that _if_ this was done with malicious intent, then maybe the hope was that doing it during a holiday would reduce response time or allow it to fly under the radar. Of course, as you say, just because it was a holiday does not inherently mean it’s malicious, it has plausible deniability.

What I actually said is that I believe that the notion of a holiday "hiding" these activities is naive. I don't think it makes any difference.

I don't know if there's a rotation or another system. I think there are probably multiple across different parties responsible for maintaining CA trust.

Post reply on HN