Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

21–30 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#23
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

after their heartbleed extortions they really deserve nothing less

(and yes, I was a paying customer)

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#24

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

With a caveat, which sends a pretty strong and clear message:

> We plan to distrust only newly-issued certificates to try and reduce the impact on web users [..] Our proposal is that we determine “newly issued” by examining the notBefore date [...] therefore WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#26
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

They're not "killing" anyone. They have reasonable doubt that the CA has misrepresented the truth and engaged in practices that violate the rules set forth by the CAB and those for inclusion in the Mozilla trust store. There will have to be consequences for else it means nothing.

They're also very clear that they do not intend to invalidate any already issued certificates, only new ones after a specific, yet to be decided, date and that they remain open to re-inclusion after the year's time-out and passing the normal inclusion tests. However, they rightfully set forth a requirement for some audits to take place by Mozilla appointed parties. For this I'm particularly thankful as if the auditors are allowed to keep doing this kind of hodge-bodge botch job the already strained trust in CA's is further weakened.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#27
post #11

I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?

Considering I believe one of the writers of this was from Google, I guess we can assume they'll likely follow?

With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#28
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

A huge factor in their popularity is their free certificate, and now Let’s Encrypt is operational. StartCom’s free certificate always seemed like a gateway to their paid offerings, because it is so limited and awkward to use. The Let’s Encrypt product is better.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#29

why is this google docs ? why is this not atleast a markdown file in github ?

From tptacek:

"It was written by multiple authors. Ryan Sleevi is at Google."

I would assume the method it was written in is of little consequence to many, just that Google Docs offer far better convenience when working in teams.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#30
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

Behaviours of StartCom and its owner WoSign that are against the accepted rules of the industry they work in, in industry for which trust if key, is killing StartCom.

Being popular does not give you the right to expect transgressions to be ignored.

I used to use StartCom and even recommend them (it was an inexpensive way to get wildcard and multi-domain certificates). Since LetsEncrypt they have far less relevance, and since recent behaviours I wouldn't trust them if they were still relevant to my needs. The one wildcard I still use (because lazy mainly) I paid for a new version of elsewhere, my other SSL needs LetsEncrypt does the job.

Post reply on HN