Live data from Hacker News

Apple's response to the WoSign incidents

groups.google.com

21–30 of 39 posts

Re: Apple's response to the WoSign incidents

#21
post #16

Sorry if this is obvious to others, but just to be clear ... As it's widely reported that WoSign has taken over StartCom's infrastructure, this implies that StartCom StartSSL Free certificates going forward won't be trusted by Apple either, correct? It also sounds a little strange to only call out the free certificates. Are they going to allow new paid OV/EV (and what they call 'IV') certificates to remain valid?

My read on the announcement is that they won't be taking action against the StartCom CA & intermediates at this time.

The WoSign existing-certs exemption probably involves a whitelist they're shipping along with the OS. A lot of the feasibility discussions on this approach have centered on the size of the required whitelist [1]. Taking the same approach with StartCom may not be possible due to the scale. Also, StartCom certificates don't have the same coverage in the Certificate Transparency logs - so the certificate dating is problematic.

Hmmm, thinking about this now, if I were Wosign, I would be having a fire sale on StartCom. Selling the brand immediately (maybe to an existing competent CA) and asking the trust store operators for understanding (probably conditioned on full CT reporting) might be a way to recoup some losses out of all this mess.

Representatives of Qihoo 360, StartCom, and Mozilla are meeting in London next week. I'm very curious what they will be discussing. [2]

[1] https://groups.google.com/d/msg/mozilla.dev.security.policy/... [2] https://groups.google.com/d/msg/mozilla.dev.security.policy/...

Re: Apple's response to the WoSign incidents

#22
post #20

Earlier quoted context omitted.

Ugh. September 19th is poor date to choose. When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point. But that was on ~26th September. Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

That seems like an odd move, doubling down on the CA after news of them doing shady stuff? Why not take that opportunity to switch to something else like let's encrypt?

Really not sure why you'd think this is "doubling down"?

We've already gone through the StartCom verification process, but had only generated a few specific cert's for subdomains.

However, we're right now in the process of launching a new online project. No idea what subdomains will be needed in very near future.

It costs us no extra to generate wildcard ones, which obviously is the right move to do as they'll be valid while StartCom's new ones are no longer trusted (when Mozilla stops accepting new certs).

There's literally no way we could afford to pay for new certs from an alternative registrar instead.

Re: Apple's response to the WoSign incidents

#23

Earlier quoted context omitted.

Ugh. September 19th is poor date to choose. When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point. But that was on ~26th September. Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

When this came up, the first thing I did was generate wildcard certs for our StartCom domains A vendor you used comes under scrutiny so your response is to double down on them? Did you have prepaid credits or something? It seems like that would have been a opportune time to migrate away from them since you'd have to redeploy certs anyways.

With StartCom, once you've gone through the personal verification procedure you don't need to pay more money for new certs, nor wildcard ones.

So, no "doubling down" involved. Just a desire to have actually working certs before Mozilla's "to be announced" cut off date happens.

And then Apple comes along and (unless I'm misunderstanding) all of our certs will be useless. :(

Re: Apple's response to the WoSign incidents

#24
post #20

Earlier quoted context omitted.

That seems like an odd move, doubling down on the CA after news of them doing shady stuff? Why not take that opportunity to switch to something else like let's encrypt?

Really not sure why you'd think this is "doubling down"? We've already gone through the StartCom verification process, but had only generated a few specific cert's for subdomains. However, we're right now in the process of launching a new online project. No idea what subdomains will be needed in very near future. It costs us no extra to generate wildcard ones, which obviously is the right move to do as they'll be val…

> There's literally no way we could afford to pay for new certs from an alternative registrar instead.

If ~$100 is that much for you (as a company of some sort) why don't you use Letsencrypt?

Re: Apple's response to the WoSign incidents

#25

Earlier quoted context omitted.

Really not sure why you'd think this is "doubling down"? We've already gone through the StartCom verification process, but had only generated a few specific cert's for subdomains. However, we're right now in the process of launching a new online project. No idea what subdomains will be needed in very near future. It costs us no extra to generate wildcard ones, which obviously is the right move to do as they'll be val…

> There's literally no way we could afford to pay for new certs from an alternative registrar instead. If ~$100 is that much for you (as a company of some sort) why don't you use Letsencrypt?

Good point, that might be the better solution for the public HTTPS part of things.

Lets Encrypt doesn't provide MS Authenticode signing certs (eg to validate our downloads are legit) though. Hopefully this whole mess doesn't scope creep to include those too.

Re: Apple's response to the WoSign incidents

#26

Earlier quoted context omitted.

When this came up, the first thing I did was generate wildcard certs for our StartCom domains A vendor you used comes under scrutiny so your response is to double down on them? Did you have prepaid credits or something? It seems like that would have been a opportune time to migrate away from them since you'd have to redeploy certs anyways.

With StartCom, once you've gone through the personal verification procedure you don't need to pay more money for new certs, nor wildcard ones. So, no "doubling down" involved. Just a desire to have actually working certs before Mozilla's "to be announced" cut off date happens. And then Apple comes along and (unless I'm misunderstanding) all of our certs will be useless. :(

You should get a refund from your cert provider.

Re: Apple's response to the WoSign incidents

#27
post #17
post #7

That should serve as a clear warning to other certificate authorities. Behave or you will be ruined. For most CAs having either Apple, Mozilla, Microsoft or Google remove your root certificate will drive customers away to the point where you might as well close up shop.

nobody has been ruined just yet. and when i look at how sheepishly slow mozilla reacts my guess is nobody will ever really get thrown out of that club. what they've done is clear. it's been misconduct as a ca. untrust them. done. fuck you.

Representatives of Google, Apple, and Mozilla have all dismissed the suitability of a fast reactionary nuclear approach.

There are plenty of innocent sites who use WoSign/Startcom certificates.

It's easy to be flippant when you're not actually responsible for a browser which users use, and need to worry about adverse side-effects. You kill WoSign overnight and you now have millions of users habituated to ignoring TLS errors, and now know how to override internal browser security settings.

Hope it was worth it.

Re: Apple's response to the WoSign incidents

#28
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

Ugh. September 19th is poor date to choose. When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point. But that was on ~26th September. Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

This announcement only pertains to the "WoSign CA Free SSL Certificate G2" intermediate CA and does not affect any StartCom-issued certificates.

They might announce similar steps for StartCom in the future, but nothing as of yet.

Re: Apple's response to the WoSign incidents

#29
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

For those who may not remember or may not have heard, QiHoo is the company behind the most popular scam browsers in the world: Qihoo 360 Secure. It was one of the most popular browsers in China with 28% of the market a few years ago. It used an IE logo colored green, force-uninstalled competing browsers by claiming they were unsafe, made uninstallation so difficult you'd often have to re-image the machine, breaks SSL…

Also accused of gaming antivirus tests http://www.pcworld.com/article/2919554/tencent-qihoo-antimal...

Re: Apple's response to the WoSign incidents

#30
post #10

Earlier quoted context omitted.

> But they will continue to "trust individual existing certificates" if they had been published to Certificate Transparency logs by September 19th. This seems even more sensible than Mozilla's existing proposal to trust the certificate notBefore date until proof of further backdated certificates.

>> But they will continue to "trust individual existing certificates" if they had been published to Certificate Transparency logs by September 19th. > This seems even more sensible than Mozilla's existing proposal to trust the certificate notBefore date until proof of further backdated certificates. The question is how they'll actually do that. This was discussed in the moz-sec-policy-thread and people came to the ro…

In the context of macOS, shipping out even a 75MB bundle of trusted certificates is "not significant".

Bundling it into the browser would increase the download size by a substantial percentage, but 75MB as a 'security update' distributed through the App Store is comparatively tiny versus the 1GB+ which is typical for 10.11 to 10.11.1 style updates.

Post reply on HN