Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

151–160 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#151

Earlier quoted context omitted.

They are a political organisation and their ideas conflict with mine. I don't keep a strong boycott on them, but I don't want to support their products, that's all.

I'd be very interested to know which of the EFF's political positions you object to, but it appears pretty clear you're avoiding answering that question...

I don't think net neutrality is a good idea. I also have far-right ideas, while they have repeatedly expressed themselves to be liberal.

I'm not the kind of person who believes in boycotting (especially in this case, where I'd be all alone it seems :-) but if I could avoid them, I would. If not, no biggie.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#152
As someone who's using StartCom for several years I'm really anxious now. I may use Let's Encrypt for a few sites but not for all and I also got my email certificates from StartCom. As far as I know there's no suitable alternative that does not cost $500+ per year, or does anyone have an advice for me?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#153
post #148

Earlier quoted context omitted.

When the story first broke, I manually untrusted WoSign's and StartCom's root certificates in OS X, instead of deleting them outright...at least I thought I did. I upgraded to macOS 10.12 Sierra this past weekend, and repeated the process. Except WoSign's certificates aren't there to begin with, though StartCom's still are. So perhaps Apple had dropped WoSign already? Would anyone else running 10.12 verify?

IIRC WoSign was never in Apple's trust store in the first place; their trust status came from StartCom cross-signing their certificates. (Not sure if cached intermediate certificates get added to the keychain - maybe that's what you saw previously?)

I can say +1. WoSign has never been in OS X trust chain as I hit this issue once before and had to install it myself manually. You can search about WoSign and OS X on Google and you will see that it was never there. If you found it in your trust store in the first place, there must be some shady business going on in your Mac. Also similar comments in this other HN thread: https://news.ycombinator.com/item?id=12389573

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#154

Earlier quoted context omitted.

If the security the CAs offer is "just theater", go spoof DNS and phish Bank of America logins; you should be able to trick users just by rolling self-signed certificates.

You do know that BofA is one of the organizations with verified bad certificates in the wild, right? This isn't just a theoretical worry. That's why it's "theater": we know that right now there are valid but bad certificates for a depressing number of entities.

Cool, how do I get one of those?

In scenario 5 or 4, it is easy for me (not "someone", me) to get one of those.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#155
post #115
post #107

Earlier quoted context omitted.

The issue you're describing is a concern for the CA/B Forum, not really all that relevant for Mozilla/mozilla.dev.security.policy. That being said, the CA/B Forum seems to be discussing the issue[1]. [1]: https://twitter.com/sleevi_/status/780454860676149248

Thank you, though the Qihoo relationship is not what I was referring to. I actually meant executing two votes in the CA/B Forum. As the connection between WoSign and StartCom was only incidentally found while investigating the other issues, I am questioning if there may be more dark sheep in the herd of CAs... we may just haven't looked hard enough. Do the Audit Requirements include checking for such relationships?

That's in all likelihood the same issue - Qihoo de facto owning two CAs who currently cast two separate votes in the CA/B Forum. Not sure if it would be a concern otherwise (i.e. if Qihoo were to own just one CA and not disclose that fact, I don't think that's relevant for the CA/B Forum, leaving aside the problem that they're also a member as a browser vendor ...)

I think the voting rules are part of the bylaws (and not the Baseline Requirements), so I'm not certain if that's something that's looked into during the audits.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#156
post #118

Nuke it from orbit. The whole idea of PKI is Broken and Wrong and confuses two different goals. Here's a fun one I noticed: Wells Fargo and several other banks are CAs. This is idiotic. The "logic" behind PKI dictates that it's a third party identifying my bank to me. If banks themselves are CAs even that fig leaf doesn't mean much. We have known bad actors in the pool of widely accepted CAs, right now. There's no se…

OK, so what do you want to happen starting tomorrow morning? * All HTTPS sites show up as trusted. Woohoo! * All HTTPS sites show up as untrusted, people are encouraged to switch to HTTP. Woohoo! * All HTTPS sites use trust-on-first-use, which means that we have a date and time announced when MITM attacks are particularly effective and will persist for a very long time. * All HTTPS sites are untrusted, except for tho…

There was a good start of an answer to that in Perspectives [1] (and later Moxie's Convergence), but sadly those projects are technically dead now.

I still think those were good idea, but nothing is ever going to replace CAs without the support of major players such as OS and browser vendors.

[1] https://perspectives-project.org/

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#157
post #78
post #62

Earlier quoted context omitted.

Ryan Sleevi authored the report in his capacity as a peer of the Mozilla CA Certificates Module, not as a Chrome/Google employee. See https://wiki.mozilla.org/CA:Policy_Participants Chrome does indeed use the platform CA store, but they can and do impose additional logic on top of it, such as requiring CT for Symantec, distrusting new CNNIC certs, or name-constraining ANSSI and India CCA.

Yes, but it begs the question why a Google employee working on Chromium is a peer of that module in the first place. It's because Google is a user, right?

It's worthwhile pointing out that many of the original Chromium developers were previously employed by Google to work on Firefox. Now, I don't know whether this is true in Ryan's case, but it doesn't seem that surprising at the end of the day.

Equally, Google ultimately has an interest in the security of the web platform (as well as its interoperability), as their entire business is built on it. They'd have a far harder time selling some of their products if people believed it to be insecure.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#158
post #116
post #106

Earlier quoted context omitted.

It's in the wiki https://wiki.mozilla.org/CA:WoSign_Issues

Could you please refer to the actual Issue? I can neither find anything related to the CA/B-Forum voting fraud nor to the yet unresolved Qihoo relationship.

Issue R? https://wiki.mozilla.org/CA:WoSign_Issues#Issue_R:_Purchase_...

Which links to

https://groups.google.com/forum/#!topic/mozilla.dev.security...

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#159
post #47
post #15

If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.

The browsers will distrust the CA. Which will, in all likelyhood, lead to their bankruptcy.

Will they? Still gotta wait for Google, Microsoft and Apple.

Is there any mechanism to push certificate updates to Android devices in the wild? Otherwise there's going to be a lot of devices that trust WoSign and StartCom, no matter what.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#160

Corporate personhood is an American thing, but if the CA can't perform their most fundamental function (certifying accurate information), isn't that the best possible case for the corporate death penalty? A 1-year time-out is insufficient to regain trust, IMO. I would never let them return, absent some kind of additional (exculpatory) information) They won't even admit to their behavior!

Corporate personhood is not an American thing. It appeared in the UK in the 1800s and it's now common across the world.
Post reply on HN