Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

211–220 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#211
While I agree that they did the wrong thing and WoSign/StartCom should be punished for lying, the whole sha-1 deprecation thing is very black and white. Others have successfully gained "exemptions" to do precisely this, and it's an interesting question whether it would have been easy for WoSign to get those same exemptions if they'd just asked. I bet the answer is "possible but not easy".

Meanwhile:

http://security.stackexchange.com/questions/86609/this-is-20...

https://www.schneier.com/blog/archives/2015/10/sha-1_freesta...

"Freestart collisions, like the one presented here, do not directly imply a collision for SHA-1"

"this work is an important milestone towards an actual SHA-1 collision"

https://en.wikipedia.org/wiki/SHA-1

"SHA-1 is no longer considered secure against well-funded opponents".

AKA, SHA-1 may not be secure against a nation state or attacker with a ton of money, but it's secure enough against for almost every site against almost every attacker. Given the reported 5%+ of Chinese browsers not supporting newer certs, I can see why customers might want a cert that gives them a lot more than nothing, though less than best-of-breed.

It's the one-size-fits-all where someone's personal blog needs to have the same level of security as the apple app store's payment system that leaves them filling a real market need. They didn't go seeking people wanting SHA1 certs, people wanting SHA1 certs that would still work went seeking someone who would provide them.

And they went seeking because the alternative is upgrading potentially millions of dollars worth of embedded kit which doesn't support newer certs, all to secure one link in a chain in which SHA1 is nowhere near the weakest link.

So yeah, the CAB chose to inflict a ton of pain and cause still-functioning hardware to be discarded in order to push a more secure ecosystem on everybody. Which is great from some perspectives, but it's environmental vandalism from another perspective, and if it pushes people back to non-HTTPS traffic for those older pieces of equipment it could cause a short term worsening of security.

(the deprecation of sha1 that is. The lying by WoSign/StartCom was a calculated risk in a business where everything is based on trust, and they lost)

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#212
post #204
post #175

Wow, this would be devastating if they actually went through with revoking their root certificate. StartCom is (well, was ) the only competition to Let's Encrypt in the free certificate space. It is far and away the cheapest direct provider of wildcard certificates (which are impossible to get for free), unless you move into reseller territory. And even their free certificates last four times as long, and don't requi…

Surely you could have demanded a refund if you had chosen StartSSL and they sold you what turned out to be a defective product?

Good luck collecting after the company's potential future revenue has been erased.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#213
post #181

Earlier quoted context omitted.

Really, either way, this is a death sentence for Wosign/Startcom. They're unlikely to survive for a year + all of the time and cost it would take to recertify without any revenue from certificate issuance. Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it wou…

> They're unlikely to survive for a year Well, they might, unless the other browser vendors do the same. Firefox is only like 10% of the total browser market (mobile included).

Browser shares vary wildly by country. For example in germany FF is still the widest used desktop browser. Including mobile probably tips it in favor of safari or chrome, but losing a substantial portion of the desktop market in Europe's largest economy will hurt you.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#214
Is there a governing body or regulatory authority which looks over the process followed by CAs ?

As a fan of firefox, I am happy that as a community, Mozilla has done the necessary ground work to reach this conclusion. However, as long as PKI remains a highly profitable business, more and more such events are going to happen.

I don't think all CAs should be trusted equally. Right now, AFAIK, my browsing experience is only as secure as the weakest CA. Hopefully, HPKP can put an end to this.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#215

Earlier quoted context omitted.

Yes, we are very fortunate to have Let's Encrypt now.

One problem - at least for the project I'm working on - is that Lets Encrypt isn't a replacement for all of StartCom. We use a StartCom "MS Authenticode" certificate to sign our releases, so Windows users don't get a warning message from the various anti-malware scanners (and similar). At first glance it sounds like Mozilla not accepting new StartCom cert's at some point won't affect that. It may snowball, but that's…

Same here, I've just recently obtained a "Class 2 Code Signing" certificate from StarCom for digital sign my Windows software - as a individual software developer from China, I don't even have alternative options - I tried purchasing from Comodo, but unfortunately there process for checking individuals from out out of the US is extremely difficult.

So I wish this would not affect the certificates StarCom issued for code signing.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#216

Earlier quoted context omitted.

You're painting 1 billion people with a rather broad brush.

No, it is pretty well established that countries have corruption problems, and cultural attitudes can be at variance to what you would expect. Many practices we would find outragously corrupt are common in China, with no recourse through the legal system. https://www.transparency.org/country/#CHN

That's a tautology. "cultural attitudes can be at variance to what you would expect" anywhere.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#217

Earlier quoted context omitted.

It's worse even than that, because a substantial portion of their customer base will need to renew during the year, and will switch to new CAs. Not only do they forgo a year of revenue, but they also begin the next year with a substantially reduced customer base.

I really appreciate the analysis. However, can WoSign resell a different CA's services for the next year without their customers noticing?

Sure, why not. A lot of "CAs" do this.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#218
I think Mozilla is falling for Symantecs / other CAs propaganda here. Yes, WoSign did bad things, but those are by far not the worst things we've seen in CA wrongdoings in the last years. We've seen certs issued for MITM attacks and security holes in the validation process of nearly every CA. (http://www.theregister.co.uk/2012/02/14/trustwave_analysis/) Bottom line: "Let's encrypt" is destroying the business of many shady CAs these days. Competition is getting harder. StartCom had an advance in this race as they adopted quickly to the new rules and the've build the best product in the market for special use cases. We - for example - rely on a lot of wildcard certs for many domains. StartCom had the product. We pay'd them $200 for all our certs and the next cheapest competitor wanted $150.000 / year for our certs. I totally get why they are getting attacked by the big players. I totally don't get why Mozilla is falling for this.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#219
post #203

Earlier quoted context omitted.

So wosign's best bet might be to call Mozilla's bluff and issue backdated certs now?

They bring that up in the document: > It is true that this date is chosen by the CA and therefore WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. However, many eyes are on the Web PKI and if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in al…

Which means it's important that they try really hard to avoid being detected.

They probably can't do it, but it's still got a better chance of success for them than staying in business for a year with no sales.

----

Edit: When I think a moment more about it, my point is silly. I realize how inconceivably impossible it is for them to avoid detection. If they sell backdated certs, one easy way to detect this would be to buy one.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#220
post #210

Earlier quoted context omitted.

Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…

Doesn't the CA have one move left in this game of brinkmanship? They can start brazenly backdating their new certificates to fall into the accepted window, which would leave us right back at holding their own customer base hostage.

This is addressed in the document as well:

WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. However, many eyes are on the Web PKI and if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.

If the CA really goes that route, it will be clear malicious behavior and therefore a good reason to permanently ban the CA.

Post reply on HN