Live data from Hacker News

Entrust Certificate Distrust

security.googleblog.com

111–118 of 118 posts

Re: Entrust Certificate Distrust

#112

Earlier quoted context omitted.

The local admin means "the user's employer's IT department", which, for the sake of a work laptop, they implicitly trust way more than Mozilla/Microsoft/Google/Apple etc who managed the public root stores.

I don't think a lot of people have the ability to prioritize employer with an IT department in the top percentile over other factors like location, pay and willingness to hire. Whether CA/B is good or bad at what it does, it puts about a thousand times more effort into the question of whether to install a CA certificate in the browser than a company that just bought the cheapest solution to one of its problems and wa…

That sounds like a problem for the IT department, not the end user?

Re: Entrust Certificate Distrust

#113
post #95

Earlier quoted context omitted.

BIMI is a CA racket.

Email logo validation and prominent display seems like a perfectly valid use case. See arguments about red-warning unencrypted HTTP and how that pushed the web to update. Add in that genAI is going to make plausible-looking phishing emails a lot easier for the world to generate en mass, and giving the everyperson something better than "decide if it looks suspicious" is important.

Warnings on unencrypted HTTP were only feasible after free certificates were widely available. BIMI doesn't have that so yes it's a racket.

Re: Entrust Certificate Distrust

#114

Earlier quoted context omitted.

I don't think a lot of people have the ability to prioritize employer with an IT department in the top percentile over other factors like location, pay and willingness to hire. Whether CA/B is good or bad at what it does, it puts about a thousand times more effort into the question of whether to install a CA certificate in the browser than a company that just bought the cheapest solution to one of its problems and wa…

That sounds like a problem for the IT department, not the end user?

Sure, their proactive attitude is why credit card fraud is referred to as "organization theft".

Re: Entrust Certificate Distrust

#115
post #45

Earlier quoted context omitted.

I am a layperson so I appreciate the attention on the matter. Regardless of how Entrust is operated, there appears to be significant complexity in CA program that the browsers operate. On the flip side, Let’s Encrypt is basically effortless for me to use, as an end user of an LE secured site and as a developer. Why misallocate all this toil on root CA compliance on the one hand, when LE could redirect that labor towa…

LE has to comply with the root CA standards too. For a variety of reasons there haven't been as many problems with LE - partly because they don't get paid by folks getting certs and issuing certs is a cost to them so their incentives are different. I don't get entrust here. It's not like they weren't told what to do.

Simplicity is a shortcut to correctness. Let's Encrypt is a simple thing to implement. Relatively speaking of course. It would be tempting (unbearably so for a for-profit issuer) to have manual issuance, this means at least duplicating the effort as every system can also be manual and must have the appropriate checks in place for that.

As an example of how wedded Let's Encrypt is to simplicity, part of routine application process is to show your certificates expire properly, often a CA would manually create a certificate which either was already expired (back dating it but arguably this is allowed for technical procedures) or had a very short lifetime and so would expire by the time the trust programme examines the demo cert. Let's Encrypt instead issued an ordinary 90 day certificate, using the same automatic process as their subscribers - and then just waited months for it to expire. Like a boss.

Re: Entrust Certificate Distrust

#116
post #95

Earlier quoted context omitted.

BIMI is a CA racket.

Email logo validation and prominent display seems like a perfectly valid use case. See arguments about red-warning unencrypted HTTP and how that pushed the web to update. Add in that genAI is going to make plausible-looking phishing emails a lot easier for the world to generate en mass, and giving the everyperson something better than "decide if it looks suspicious" is important.

Logos are bound to trademarks, which are split by country and type of business. Anybody could get a BIMI of a duplicate of your logo if they just register a different trademark in some different business (and/or country). Therefore, BIMI does not guarantee what they say they do – logo trustworthiness – and is therefore a scam. If your trademark is not valid and known globally, BIMI does nothing for you. This explains why only huge entities – i.e. with such trademarks – have ever expressed any interest.

A dead giveaway would otherwise have been that the BIMI issuers are all the now-panicking EV certificate issuers, which nobody will now buy.

Post reply on HN