Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

201–210 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#201

Earlier quoted context omitted.

I'd be very interested to know which of the EFF's political positions you object to, but it appears pretty clear you're avoiding answering that question...

I don't think net neutrality is a good idea. I also have far-right ideas, while they have repeatedly expressed themselves to be liberal. I'm not the kind of person who believes in boycotting (especially in this case, where I'd be all alone it seems :-) but if I could avoid them, I would. If not, no biggie.

Fair enough. It's not often I see anti-EFF folks, so I appreciate the elaboration.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#202
post #172
post #152

As someone who's using StartCom for several years I'm really anxious now. I may use Let's Encrypt for a few sites but not for all and I also got my email certificates from StartCom. As far as I know there's no suitable alternative that does not cost $500+ per year, or does anyone have an advice for me?

I hate to say it, but if you need the functionality that Let's Encrypt won't offer (wildcard certificates, longer validity lengths, not wanting/needing to run certbot, code signing, etc) ... your best bet is to look for the SSL resellers. I'm not going to name the one I used (as I'm not marketing for them), but I purchased a three-year AlphaSSL wildcard certificate recently for a little over $110 (for all three years…

It ... absolutely defies common sense that certificate resellers are a thing

I think that's the kind of thing you should expect in any market where the cost of serving a new customer is dominated by the marketing & sales costs in acquiring that customer.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#203
post #128

Earlier quoted context omitted.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…

So wosign's best bet might be to call Mozilla's bluff and issue backdated certs now?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#204
post #175

Wow, this would be devastating if they actually went through with revoking their root certificate. StartCom is (well, was ) the only competition to Let's Encrypt in the free certificate space. It is far and away the cheapest direct provider of wildcard certificates (which are impossible to get for free), unless you move into reseller territory. And even their free certificates last four times as long, and don't requi…

Surely you could have demanded a refund if you had chosen StartSSL and they sold you what turned out to be a defective product?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#205
post #121
post #61

Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing certs (while still manually checking every cert request, at least for any OV&EV cert in my case). This entire WoSign acquisition is incredibly shady. Shortly after that some of the customer reps had chinese names, service quality declined and we got offered to…

What use case do you have for wildcards that you can't use Let's Encrypt or similar automated issuance? Just curious, as I've yet to hear a terribly compelling one...

Not the parent, but wildcard certs are necessary for compatibility with clients that don't support SNI (ex: IE on WinXP)

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#206
post #119

Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?

Do people use S/MIME with the standard (web-based) trust stores? If you're using it with a small group of people you're in communication with, you can always generate your own CA pretty easily with the openssl command. (Except for the part about the openssl command, this is what Exchange does: everyone joined to an Active Directory domain gets config from the AD servers, so AD generates its own CA for S/MIME certs an…

I am not a fan of Microsoft in any way and, fortunately, rarely have to touch a Windows box anymore. In a previous life, however, I was responsible for integrating UNIX/Linux systems in a Windows-based environment (i.e., a large organization with thousands of users).

Microsoft's CA services (in Windows) is actually an awesome product. You can create your own root CAs and intermediates and use the included templates or build your own to (automatically) issue certificates for anything and everything that needs to communicate (users, web servers, file servers (including encryption for data at rest), e-mail, etc.).

The CA services are one of the few things I will happily concede that Microsoft did "right" (along with Active Directory and SQL Server).

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#207
post #203

Earlier quoted context omitted.

Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…

So wosign's best bet might be to call Mozilla's bluff and issue backdated certs now?

They bring that up in the document:

> It is true that this date is chosen by the CA and therefore WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. However, many eyes are on the Web PKI and if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#208

Earlier quoted context omitted.

there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…

> Connecting to TLS to news.ycombinator.com is nice in that I know nobody has read or altered the message in transit. The fact that a third party vouches that news.ycombinator.com is who they say they are doesn't add anything for me, because I don't trust news.ycombinator.com any more than I would trust somebody impersonating news.ycombinator.com. The CA in this situation simply complicates things and adds nothing fo…

I /think/ that bandrami is trying to advocate for a DNSSEC/DANE based system for certificate trust which would put the trust in the DNS operators in lieu of the CAs, and be more about asserting "control over domain" than the "is the correct legal entity" that OV/EV (but not DV) certs claim.

I'm personally not a huge fan, but (if I'm interpreting her/his argument correctly), it'd at least be secure against a casual MITM.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#210
post #128

Earlier quoted context omitted.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…

Doesn't the CA have one move left in this game of brinkmanship? They can start brazenly backdating their new certificates to fall into the accepted window, which would leave us right back at holding their own customer base hostage.
Post reply on HN