Live data from Hacker News

Entrust Certificate Distrust

security.googleblog.com

21–30 of 118 posts

Re: Entrust Certificate Distrust

#21
post #20
post #17

Earlier quoted context omitted.

Certificate transparency prevents this style of attack.

As long as the victims are checking it and know what to look for!

Chrom(e/ium) and Safari don't trust certificates that are not in public logs [0].

[0] https://en.wikipedia.org/wiki/Certificate_Transparency#Manda...

Re: Entrust Certificate Distrust

#23
post #5

I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything

Entrust makes a ton of revenue from hardware-related products (for example, printing ID cards), so it is far from the end.

Right up until the next contract renewal. "Not trustworthy enough to secure a basic website" isn't exactly a great look.

Re: Entrust Certificate Distrust

#24
post #9

Can someone ELI5 what the violations linked in the first line are? They seem pretty minor to me but I don't understand certs

Correct, the violations are minor and should be trivial to deal with.

The problem in this case is that Entrust displayed a complete disinterest into actually solving the underlying issues. Doing an oopsie is one thing. Doing an oopsie, lying about it, refusing to take precautions, and failing to take measures to prevent a repeat despite promising to do so? Completely different story.

If they can't be trusted to respond properly to minor administrative issues, why should they be trusted to respond adequately during a real security incident?

Re: Entrust Certificate Distrust

#25

It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?

I’m really impressed. CAs are 100% rent-seeking businesses and their position is solely derived from having convinced browser and OS vendors to put them in a list. You’d assume their top prio would be to stay in the list.

Re: Entrust Certificate Distrust

#27

It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?

They genuinely believe they are "too big to fail". They've got thousands of employees, they've been around for 30 years, they are a critical part of public infrastructure: surely something as trivial as a few weirdos in a mailing list couldn't instantly kill their entire business?

Stuff like this happens when upper management has zero clue about the business they are in. They believe they are in the business of selling certificates, while in reality they are in the business of selling trust. They treat things like the CA/B Forum and the various Root Programs as more like an optional networking event than the combination of judge, jury, and executioner that it actually is - with a completely predictable outcome.

Re: Entrust Certificate Distrust

#28
post #2

Some popular users: chase.com aa.com

api.cybersource.com This is gonna cause me some headaches, along with everyone else who processes payments through Cybersource, and possibly others :(

CYBS Engineer here.

We're already working on it. Keep an eye for merchant notifications if you use certificate pinning.

Now, back to rotating certificates....

Re: Entrust Certificate Distrust

#29
post #20
post #17

Earlier quoted context omitted.

Certificate transparency prevents this style of attack.

As long as the victims are checking it and know what to look for!

There's definitely a lot of people watching CT for anomalies (I'm one of them), but more surveillance of it is also good and something I've been trying to advocate.

It's also why I'm personally against SMIME and think it's a bad idea.

Re: Entrust Certificate Distrust

#30
post #5

I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything

Entrust has BIMI certs which use a different root (CN = Entrust Verified Mark Root Certification Authority - VMCR1) and for which your choices of a BIMI certificate are: Entrust or Digicert. I doubt it makes as much money as their web certs (BIMI certs are not super common, and they are expensive to issue since there's an actual validation process that typically involves a public notary validating the ID of a corpora…

BIMI is a CA racket.
Post reply on HN