Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

171–180 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#171
post #128

Earlier quoted context omitted.

The people saying this is "generous" are making largely irrational arguments. What Mozilla is proposing is the worst case for incumbent CAs.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

Really, either way, this is a death sentence for Wosign/Startcom. They're unlikely to survive for a year + all of the time and cost it would take to recertify without any revenue from certificate issuance.

Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it would do is immediately put a bunch of their innocent customers in immediate pain, for essentially no gain. It might also send the message to, say, Symantec, that they can get away with anything, because no browser would risk revoking 30+% of the web instantly. Establishing a procedure that allows for executing a CA of any size puts everyone on notice.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#172
post #152

As someone who's using StartCom for several years I'm really anxious now. I may use Let's Encrypt for a few sites but not for all and I also got my email certificates from StartCom. As far as I know there's no suitable alternative that does not cost $500+ per year, or does anyone have an advice for me?

I hate to say it, but if you need the functionality that Let's Encrypt won't offer (wildcard certificates, longer validity lengths, not wanting/needing to run certbot, code signing, etc) ... your best bet is to look for the SSL resellers.

I'm not going to name the one I used (as I'm not marketing for them), but I purchased a three-year AlphaSSL wildcard certificate recently for a little over $110 (for all three years, so less than $40/yr.)

It ... absolutely defies common sense that certificate resellers are a thing; but indeed it's the very same certificate I'd have gotten had I paid $150/yr on AlphaSSL's site.

The CA model is just completely broken. But right now, our only choice is to find the lowest amount of money to be taken for if we want full HTTPS functionality. And at the moment, that's with the resellers :/

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#173
post #13

>We also hope the public can see that when there are allegations of CA wrongdoing, Mozilla is committed to a fair, transparent and thorough investigation of the facts of each case. I'm very happy to see the way Mozilla handled this incident, both with the process and the conclusion. I have a moderate trust in the CA ecosystem as a whole, but I'm glad to see that overwhelming incompetence, if not outright maliciousnes…

>In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed

Given the risks that screwups have to their business, I would think CAs would VOLUNTARILY do this.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#174
post #128

Earlier quoted context omitted.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

Really, either way, this is a death sentence for Wosign/Startcom. They're unlikely to survive for a year + all of the time and cost it would take to recertify without any revenue from certificate issuance. Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it wou…

It's worse even than that, because a substantial portion of their customer base will need to renew during the year, and will switch to new CAs. Not only do they forgo a year of revenue, but they also begin the next year with a substantially reduced customer base.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#175
Wow, this would be devastating if they actually went through with revoking their root certificate.

StartCom is (well, was) the only competition to Let's Encrypt in the free certificate space. It is far and away the cheapest direct provider of wildcard certificates (which are impossible to get for free), unless you move into reseller territory. And even their free certificates last four times as long, and don't require the use of certbot.

Certainly, Let's Encrypt works great for a lot of peoples' needs. But for those it doesn't (and there's more of them than you might think), this is seriously bad news.

It's easy to get onboard wanting to punish WoSign/StartCom here, but keep in mind that this has the potential to screw over all of their innocent customers as well. (Future customers with the first action; all customers if the second action comes to pass and they revoke the root CA.) And screwing them could likely mean they abandon HTTPS completely instead.

Note that I am not advocating for Mozilla to give them a pass; far from it. If anything, this is just one more indictment on the long list of reasons why the entire CA system is completely broken.

I actually just recently purchased a certificate, and had my choices narrowed down to StartSSL or AlphaSSL. I am really glad I went with the latter right about now. I can't tell you how absolutely livid I would become if Mozilla ended up revoking my root CA after dropping over $100 on my certificate.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#176
post #47

Earlier quoted context omitted.

The browsers will distrust the CA. Which will, in all likelyhood, lead to their bankruptcy.

Will they? Still gotta wait for Google, Microsoft and Apple. Is there any mechanism to push certificate updates to Android devices in the wild? Otherwise there's going to be a lot of devices that trust WoSign and StartCom, no matter what.

Chrome doesn't have their own certificate store, instead they use the platform's certificate store with some logic layered on top (e.g. requiring new Symantec certificates to be in the certificate transparency logs). So an update to the Chrome app on Android could implement Mozilla's plan, or something even more extreme.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#177

Earlier quoted context omitted.

Really, either way, this is a death sentence for Wosign/Startcom. They're unlikely to survive for a year + all of the time and cost it would take to recertify without any revenue from certificate issuance. Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it wou…

It's worse even than that, because a substantial portion of their customer base will need to renew during the year, and will switch to new CAs. Not only do they forgo a year of revenue, but they also begin the next year with a substantially reduced customer base.

Is that why they apparently have started handing out free 3 year certificates?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#178
post #89

I'm not going to defend WoSign/StartCom's shady tactics, but the way the deprecation of SHA1 was performed puts people in a pretty shitty position. You can't support Windows XP users who use IE anymore with HTTPs. In the western world, that number is very small. It's around 1% still using XP and most of those people are probably not using IE anymore. In china though, that number is still >5%, and I got that number pe…

> You can't support Windows XP users who use IE anymore with HTTPs. Sure you can. Just ask a CA that has an old root trusted by XP but no longer trusted by modern browsers, and they'll issue a SHA-1 cert for you without risking to get kicked out of the truststores.

Well I guess you just discovered WoSign's next business plan! Haha

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#179
post #172
post #152

As someone who's using StartCom for several years I'm really anxious now. I may use Let's Encrypt for a few sites but not for all and I also got my email certificates from StartCom. As far as I know there's no suitable alternative that does not cost $500+ per year, or does anyone have an advice for me?

I hate to say it, but if you need the functionality that Let's Encrypt won't offer (wildcard certificates, longer validity lengths, not wanting/needing to run certbot, code signing, etc) ... your best bet is to look for the SSL resellers. I'm not going to name the one I used (as I'm not marketing for them), but I purchased a three-year AlphaSSL wildcard certificate recently for a little over $110 (for all three years…

It's funny but I've seen the same thing with virtual carriers for mobile phones. The big name brand can charge a premium because lots of people feel uneasy going with a no-name service. Then they turn around and grab the rest of the market, the price conscious consumers, with an off-brand, avoiding damaging their big name revenue. I'm sure there's even people believing "if it costs more it must be better".

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#180
post #61

Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing certs (while still manually checking every cert request, at least for any OV&EV cert in my case). This entire WoSign acquisition is incredibly shady. Shortly after that some of the customer reps had chinese names, service quality declined and we got offered to…

What would being an "Intermediate CA" actually mean in practise?

Am I right in thinking I could generate my own certificates for any domain I wanted and have them validate in any browsers or devices that currently trust StartSSL/WoSign? Or to put it another way, would it give me the same powers as running my own internal CA but without the problem of convincing people to install my root-ca?

I assume it _can't_ mean that, otherwise people would surely be up in arms (10k to mitm anyone is scarily cheap), so could someone educate me please?

Post reply on HN