Earlier quoted context omitted.
Certificate transparency prevents this style of attack.
As long as the victims are checking it and know what to look for!
[0] https://en.wikipedia.org/wiki/Certificate_Transparency#Manda...
21–30 of 118 posts
Earlier quoted context omitted.
Certificate transparency prevents this style of attack.
As long as the victims are checking it and know what to look for!
[0] https://en.wikipedia.org/wiki/Certificate_Transparency#Manda...
[flagged]
I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything
Entrust makes a ton of revenue from hardware-related products (for example, printing ID cards), so it is far from the end.
Can someone ELI5 what the violations linked in the first line are? They seem pretty minor to me but I don't understand certs
The problem in this case is that Entrust displayed a complete disinterest into actually solving the underlying issues. Doing an oopsie is one thing. Doing an oopsie, lying about it, refusing to take precautions, and failing to take measures to prevent a repeat despite promising to do so? Completely different story.
If they can't be trusted to respond properly to minor administrative issues, why should they be trusted to respond adequately during a real security incident?
It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?
Some popular users: chase.com aa.com
This is gonna cause me some headaches, along with everyone else who processes payments through Cybersource, and possibly others :(
It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?
Stuff like this happens when upper management has zero clue about the business they are in. They believe they are in the business of selling certificates, while in reality they are in the business of selling trust. They treat things like the CA/B Forum and the various Root Programs as more like an optional networking event than the combination of judge, jury, and executioner that it actually is - with a completely predictable outcome.
Some popular users: chase.com aa.com
api.cybersource.com This is gonna cause me some headaches, along with everyone else who processes payments through Cybersource, and possibly others :(
We're already working on it. Keep an eye for merchant notifications if you use certificate pinning.
Now, back to rotating certificates....
Earlier quoted context omitted.
Certificate transparency prevents this style of attack.
As long as the victims are checking it and know what to look for!
It's also why I'm personally against SMIME and think it's a bad idea.
I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything
Entrust has BIMI certs which use a different root (CN = Entrust Verified Mark Root Certification Authority - VMCR1) and for which your choices of a BIMI certificate are: Entrust or Digicert. I doubt it makes as much money as their web certs (BIMI certs are not super common, and they are expensive to issue since there's an actual validation process that typically involves a public notary validating the ID of a corpora…