Can someone explain what could be done with that and by whom?
The brower (possibly only edge) and system would show the connection as being secure.
21–30 of 233 posts
Can someone explain what could be done with that and by whom?
The brower (possibly only edge) and system would show the connection as being secure.
Can someone explain what could be done with that and by whom?
Earlier quoted context omitted.
These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…
Windows is less popular every year.
This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.
What is even the point of a web CA that isn't trusted by all of the major players? Is there one?
Earlier quoted context omitted.
What is even the point of a web CA that isn't trusted by all of the major players? Is there one?
These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…
ICP-Brasil officially stopped emitting public-facing SSL/TLS certificates in October: https://www.gov.br/iti/pt-br/assuntos/noticias/indice-de-not... This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good.
Earlier quoted context omitted.
These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…
what's the state's interest in having their CA built into windows?
Large enterprises in the US generally have the same capability, but not loaded into operating systems by default (that is: Walmart's ability to do this on its own network in no way impacts you, who have never worked on that network).
Not clear (to me) in the original post -- was this done accidentally or intentionally?
Can someone explain what could be done with that and by whom?
Whomever has this fake certificate can run a server and say it's google.com and windows will say "yep you are" with the little green lock.
And without DNS pointing google.com to that IP address, it's pretty useless.
Not clear (to me) in the original post -- was this done accidentally or intentionally?