Live data from Hacker News

Remediation Plan for WoSign and StartCom

groups.google.com

21–30 of 54 posts

Re: Remediation Plan for WoSign and StartCom

#21
post #5

It's really great to see E&Y HK being held to account on this also. :thumbs_up:

Why just HK, though?

From my reading: because it was only E&Y HK that was found to be delinquent in their obligations, and there isn't evidence that it's a systemic issue. IMHO: there should be a full audit of E&Y practises globally in order to continue to perform services pertaining to the certificate process.

Re: Remediation Plan for WoSign and StartCom

#23
I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so.

I hope their learn their lesson, and try to be more honest in the future!

Re: Remediation Plan for WoSign and StartCom

#26
post #20

I dont like this route. The only value for the WoSign keys for a whole year would be issuing certificates with a doctored notBefore date, and they can't do that publically.

It's an attempt to avoid instantly breaking all the sites across the web using WoSign/StartCom certificates. A year should give customers enough time to learn about the issue and switch providers. Meanwhile, WoSign can't sign up new customers or renew existing ones (at least, not if they want those new certs to work in Firefox).

Re: Remediation Plan for WoSign and StartCom

#28
post #22

I wish I could replace my OS's certificate store with Mozilla's.

The full cert store data is here, if you'd like to try: https://hg.mozilla.org/mozilla-central/raw-file/tip/security...

Assuming the notBefore date logic is going to be implemented in Mozilla's Network Security Services library the task would be to replace the OS's security library, which is probably not possible.
Post reply on HN