Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

141–150 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#141

Earlier quoted context omitted.

> an even worse look for Microsoft. Microsoft have a terrible reputation for security, which they've earned through doing stuff like this. It's not likely to get any better any time soon either, as their trajectory is still pointed downwards.

I don’t know enough to comment on that reputation, but this surprises me. They’re known for being great at serving and selling to the enterprise, frequently at the expense of end users, and big enterprises/govts care a lot about security usually. Even if much of that caring is box ticking rather than actually looking into the security (hello ISO27001), you’d expect it to result in generally a security conscious cultu…

It's hit and miss.

They have one of the largest cyber security operations worldwide and regularly track and dismantle criminal operations. There's some great people working there.

Then there's Azure. Which is used by large organizations and you would expect it to have the utmost care when it comes to security. But it often does badly, in several instances it allowed different tenants to access information from one another, something unheard of on AWS. For example: https://www.securityweek.com/microsoft-patches-azure-cross-t... or https://www.theregister.com/2024/06/05/tenable_azure_flaw/ or https://borncity.com/win/2023/08/03/microsoft-as-a-security-...

There are so many cross tenant vulnerabilities that there could be some overlap in those URLs, and it's a bit late at night for me to read those carefully, but you get the idea.

They do get the most flak about Windows, which used to be a non networked, single user OS.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#142

Earlier quoted context omitted.

> an even worse look for Microsoft. Microsoft have a terrible reputation for security, which they've earned through doing stuff like this. It's not likely to get any better any time soon either, as their trajectory is still pointed downwards.

I don’t know enough to comment on that reputation, but this surprises me. They’re known for being great at serving and selling to the enterprise, frequently at the expense of end users, and big enterprises/govts care a lot about security usually. Even if much of that caring is box ticking rather than actually looking into the security (hello ISO27001), you’d expect it to result in generally a security conscious cultu…

> Even if much of that caring is box ticking rather than actually looking into the security (hello ISO27001), you’d expect it to result in generally a security conscious culture.

If the whole value is in ticking the box, why would that develop a culture that values anything more than the tick?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#143
post #107
post #28

Earlier quoted context omitted.

The certificate was registered in CT, so a reasonable assumption would be that this was accidental, because it was guaranteed to be noticed and to generate drama that would threaten the capability they arranged, presumably at some significant expense.

What is CT here? Central Time? Connecticut? Maybe Certificate Transparency? I guess that last one might make the most sense. Abbreviations are hard.

Certificate Transparency, all CA's log their issued certificates to central log servers, managed by Cloudflare, google etc. If this is not done, the certificate will not be seen as trusted by Browsers. It was designed to have a publicly auditable source of issued certificates, exactly so we can notice rogue google.com certs.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#144
post #22

Can someone explain what could be done with that and by whom?

Whomever has this fake certificate can run a server and say it's google.com and windows will say "yep you are" with the little green lock.

Where? In Edge you mean?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#145

Earlier quoted context omitted.

I don’t know enough to comment on that reputation, but this surprises me. They’re known for being great at serving and selling to the enterprise, frequently at the expense of end users, and big enterprises/govts care a lot about security usually. Even if much of that caring is box ticking rather than actually looking into the security (hello ISO27001), you’d expect it to result in generally a security conscious cultu…

> Even if much of that caring is box ticking rather than actually looking into the security (hello ISO27001), you’d expect it to result in generally a security conscious culture. If the whole value is in ticking the box, why would that develop a culture that values anything more than the tick?

The cycle usually goes something like box ticking, complacency, security scare, remediation, rinse and repeat.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#147
post #97

Earlier quoted context omitted.

Users can tune their own trust stores.

Is there a way to do it that isn't tedious? I'm not familiar with tooling beyond the UI browsers offer, which doesn't match the experience I was trying to describe.

I mean... It's as easy as getting SSL certs and importing them into a trust store/adding them to a directory.

The hard part is getting the people you want to establish a trust relationship with to give you a copy of their key. Web of Trust was the answer to logistical key distribution problem. The idea being there would be an organization that would vet people and vouchsafe their cryptographic material for everyone else.

The problem of course, is that the more invisible this is to users, and the more unintuitive the actual mechanics, the more valuable cracking the CA's becomes for hostile actors because of the ensuing blast radius compared to the boast radius that would result from theoretically getting the practice of key exchange in the public, and getting them to internalize the act of creating their own trust networks.

Of course, if you have dreams or fantasies of being able to control people, none of the work that goes into educating the populace is ever going to be endorsed, because once everyone realizes that they can at least assure their own safety by not delegating their cryptography, the entire idea of eacesdropping as a third-party by tapping the line is unmade. Which is not a popular state of affairs universally.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#148
post #16

Earlier quoted context omitted.

Windows is less popular every year.

I looked at the graphs at Statista. I don’t think it’s so clear cut. Mobile OSs have pushed it down, but it seem to dominate PC market. Do you have a graph that shows its decline on computers, not mobile phones? Or in absolute unit counts?

I think that might be a bit of an unfair caveat. People do real work on mobile OSes. They shop and communicate on mobile OSes, and occasionally organise revolutions.

(Although I'm not sure why "Netraft confirms, Windows is dying" is a useful comment here anyway. Windows is a behemoth.)

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#149
post #49

Earlier quoted context omitted.

So they can mitm their own employees without annoying TLS warnings.

To be clear, this is bog standard in all mega-corps now. They have a vendor product that provides HTTP Internet proxy, then they perform MitM to decrypt HTTPS traffic and re-sign/encrypt with in-house issued cert. Then, this cert is auto-trusted as part of all base OS installations. To be honest, how else can mega-corps spy on HTTPS traffic without this MitM tactic? I don't know any other way.

Yes, but normally this is done by making your own CA and installing it into your client devices, not by getting it into every device globally by working with Microsoft.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#150
post #16

Earlier quoted context omitted.

Windows is less popular every year.

I looked at the graphs at Statista. I don’t think it’s so clear cut. Mobile OSs have pushed it down, but it seem to dominate PC market. Do you have a graph that shows its decline on computers, not mobile phones? Or in absolute unit counts?

https://gs.statcounter.com/os-market-share/desktop/worldwide...

There's a clear but slow trend on desktop.

Jan 2009: 95.4% Windows

Jan 2016: 85.2% Windows

Jan 2024: 73.0% Windows

In e.g. US it's going down faster, desktop market share now at 62%:

https://gs.statcounter.com/os-market-share/desktop/united-st...

Post reply on HN