"Trustico’s CEO indicated that Trustico held the private keys for those certificates, and then emailed us approximately 20,000 certificate private keys." Well, that's one way to ensure they're considered "comprimised".
> How is this not related to "the big distrust"? Unreal. If you mean the Symantec distrust - it's financially related but not technically related. In particular, it looks like Trustico ended their business agreement with Symantec (over the Symantec distrust) and signed a new contract with Comodo to resell Comodo certs instead. They wanted to move all their customers to the Comodo certs, and asked Digicert, the new ow…
Thank you for your explanation. I remember part of the Symantec problem was the uncontrolled resellers practices. Isn't this just some more dust under the rag coming out now?
Probably. In some amount of fairness, Trustico's stated motivation was that they didn't feel like they trusted Symantec (reasonable!) and the same people were involved with the move to Digicert (which I think is correct, some employees moved but technical oversight should have moved to the more organizationally-competent Digicert team) and the same problems were likely to happen again (I think Digicert is generally good at being a competent CA, but it's not unreasonable for them to decide the risk is too high if some of the same people were around).
They also state in the MDSP thread, "We were also a victim whereby Symantec mis-issued SSL Certificates owned by us, subsequently we were asked to keep the matter quiet, under a confidentially notice."
Help me understand: this CEO has 20k private certificates he obviously should never have seen, yet alone stored. How is this not related to "the big distrust"? Unreal.
> How is this not related to "the big distrust"? Unreal. If you mean the Symantec distrust - it's financially related but not technically related. In particular, it looks like Trustico ended their business agreement with Symantec (over the Symantec distrust) and signed a new contract with Comodo to resell Comodo certs instead. They wanted to move all their customers to the Comodo certs, and asked Digicert, the new ow…
This is all kinds of crazy at the same time.
Why would Trustico want to revoke certificates under the previous root anyway? Why not just start issuing certificates under the new, and just skip the part about broadcasting their little secret to the world?
I recently learned in my security class that certificates are the way by which domains are publicly identified. But I don’t understand why there hasn’t been any alternatives besides trusting these companies to issue certificates...
It would be really hard to keep everyone's browsers/operating systems updated with a list of certificates as they're generated and renewed.
You pretty much have to concentrate it down to a small subset of trusted certificate authorities to sign your certificate.
Also, it should be a way to verify that random people aren't able to get certificates on behalf of a domain they don't own (there's nothing stopping me from generating a cert for google.com - but it should be impossible for me to get it trusted by your browser).
The situation is unfolding in this Mozilla security policy mailing list thread: https://groups.google.com/forum/m/#!topic/mozilla.dev.securi...
I hope it's not overly pedantic to point out that what you linked to is not a CAB forum thread. That's a thread on the Mozilla security policy list, which many root programs and CAs make use of for disclosure and discussion.
CAB forum has its own lists elsewhere. A relevant difference is that CAB forum discusses creating and modifying policy but is not involved in enforcement. The root programs typically deal with enforcement.
The situation is unfolding in this Mozilla security policy mailing list thread: https://groups.google.com/forum/m/#!topic/mozilla.dev.securi...
I hope it's not overly pedantic to point out that what you linked to is not a CAB forum thread. That's a thread on the Mozilla security policy list, which many root programs and CAs make use of for disclosure and discussion. CAB forum has its own lists elsewhere. A relevant difference is that CAB forum discusses creating and modifying policy but is not involved in enforcement. The root programs typically deal with en…
The DV CA space is such a mess. I still wish DV certificate issuance was the responsibility of the domain registrar, with technical measures taken to prevent competing registrars from misissuance. This way, you don't need to play whack-a-mole around your certificates, just pick a reputable registrar when you buy your domain, avoid the need to "prove" you hold the domain (your registrar control panel is today already the sole security barrier protecting your domain), and avoid the possibility that a third party can play the impostor game. And it would bring some meaning back to the reputation of different TLDs and their various registrars.