Live data from Hacker News

The SSL Co-operative: A Member-Controlled Certification Authority

sslcoop.org

21–30 of 90 posts

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#21
There's an assumption in this that domain validated certificates can be wholly automated. But, in the same way that spammers seek out open SMTP relays, phishers seek out weak SSL validation systems for use in setting up phishing sites.

CA's currently maintain internal keyword warning systems that flag domain validated requests for manual intervention. Anything that even hints that it is involved with a major company, church, charity, bank or financial institution gets flagged and approved manually.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#22
post #12

Earlier quoted context omitted.

Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't…

Mozilla created https://publicsuffix.org/ - perhaps that could help with com.au vs. example.com.au?

That's brilliant. I was wondering if there was a list that actually provided the relevant information. Thanks for the link.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#23
post #19
post #18

Earlier quoted context omitted.

Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…

This breaks for obvious cases such as mzzafr2pr.blogspot.com

Not really, as while you can make the domain exist you can't make the TXT record appear in DNS.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#24
post #5

Am I the only one that finds it hillarious (or troubling) that the SSL cert for this site is for a different host name?

Yes, let's trust these people to run a certificate authority when they aren't competent enough to set up SSL properly on their own site...

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#25
post #19
post #18

Earlier quoted context omitted.

Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…

This breaks for obvious cases such as mzzafr2pr.blogspot.com

How so? You would still be subject to clicking on the link in the standard email sent to webmaster@blogspot.com to prove you owned the root.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#26

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

StartCom charges $60 for a wildcard certificate that will be accepted by just about every important browser out there. You might even be able to get them cheaper elsewhere.

There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#27

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

With all the cheap SSL providers[0] today, I don't really have an issue buying the certificates anymore. When they used to cost a small fortune, I was really restrained to buy a certificate for every small web project, but now the situation has improved.

[0] - https://getssl.me/

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#28
post #19
post #18

Earlier quoted context omitted.

Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…

This breaks for obvious cases such as mzzafr2pr.blogspot.com

You both have to prove that you own the ability to create dns (with blogspot sorta) and the actual content. The CA provider both lists the record name and value.

You do have a good point though. I'm sure there are some services right now that allow decent control of a chosen subdomain's dns, but don't mean for you to be able to create ssl certs valid for all other subdomains too. Perhaps there should be a blacklist of sites like "blogspot". Perhaps there should be a way for a domain to indicate that wildcard certs cannot be automatically created for it without passing other conditions.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#29
post #17

Earlier quoted context omitted.

What about this post makes you think the NSA is or would be involved?

I think the question you should ask yourself is: how is the NSA involved in the currently established CA system? The answer (to your question) is , the very same way. Besides, who does think that having an alternative CA provider is going to change anything? The crypto empowering security nowadays is un-trusted, implementations proven containing backdoors, and on the top of that all the implementations are written in…

How is the NSA involved in the currently established CA system?

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#30

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

StartCom charges $60 for a wildcard certificate that will be accepted by just about every important browser out there. You might even be able to get them cheaper elsewhere. There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.

I disagree, I think free would be a significant difference. A low barrier vs. no barrier.
Post reply on HN