Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

21–30 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#21

Can someone explain what could be done with that and by whom?

Whoever has the private certificate can pretend to be google.com to people using windows.

The brower (possibly only edge) and system would show the connection as being secure.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#23
post #16

Earlier quoted context omitted.

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

Windows is less popular every year.

I looked at the graphs at Statista. I don’t think it’s so clear cut. Mobile OSs have pushed it down, but it seem to dominate PC market. Do you have a graph that shows its decline on computers, not mobile phones? Or in absolute unit counts?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#24
post #7

This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

[deleted]

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#25
post #7

Earlier quoted context omitted.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

what's the state's interest in having their CA built into windows?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#26

ICP-Brasil officially stopped emitting public-facing SSL/TLS certificates in October: https://www.gov.br/iti/pt-br/assuntos/noticias/indice-de-not... This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good.

[flagged]

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#27

Earlier quoted context omitted.

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

what's the state's interest in having their CA built into windows?

States are themselves extraordinarily large IT enterprises, they generally want control of traffic and its transparency or protection, and they are large enough to get arrangements for that, though usually not this particular arrangement.

Large enterprises in the US generally have the same capability, but not loaded into operating systems by default (that is: Walmart's ability to do this on its own network in no way impacts you, who have never worked on that network).

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#28

Not clear (to me) in the original post -- was this done accidentally or intentionally?

The certificate was registered in CT, so a reasonable assumption would be that this was accidental, because it was guaranteed to be noticed and to generate drama that would threaten the capability they arranged, presumably at some significant expense.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#29
post #22

Can someone explain what could be done with that and by whom?

Whomever has this fake certificate can run a server and say it's google.com and windows will say "yep you are" with the little green lock.

The certificate is for a specific IP address, no?

And without DNS pointing google.com to that IP address, it's pretty useless.

Post reply on HN