Shouldn't it be under the mozilla.org domain?
WoSign and StartCom: Mozilla’s proposed conclusion
21–30 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#22Just curiosity: since this report is a Google Doc, how can one know that it has been really written by Mozilla? Shouldn't it be under the mozilla.org domain?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#23Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
(and yes, I was a paying customer)
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#24A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
> We plan to distrust only newly-issued certificates to try and reduce the impact on web users [..] Our proposal is that we determine “newly issued” by examining the notBefore date [...] therefore WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#25Re: WoSign and StartCom: Mozilla’s proposed conclusion
#26Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
They're also very clear that they do not intend to invalidate any already issued certificates, only new ones after a specific, yet to be decided, date and that they remain open to re-inclusion after the year's time-out and passing the normal inclusion tests. However, they rightfully set forth a requirement for some audits to take place by Mozilla appointed parties. For this I'm particularly thankful as if the auditors are allowed to keep doing this kind of hodge-bodge botch job the already strained trust in CA's is further weakened.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#27I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?
With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#28Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#29why is this google docs ? why is this not atleast a markdown file in github ?
"It was written by multiple authors. Ryan Sleevi is at Google."
I would assume the method it was written in is of little consequence to many, just that Google Docs offer far better convenience when working in teams.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#30Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
Being popular does not give you the right to expect transgressions to be ignored.
I used to use StartCom and even recommend them (it was an inexpensive way to get wildcard and multi-domain certificates). Since LetsEncrypt they have far less relevance, and since recent behaviours I wouldn't trust them if they were still relevant to my needs. The one wildcard I still use (because lazy mainly) I paid for a new version of elsewhere, my other SSL needs LetsEncrypt does the job.