Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

211–220 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#211

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

> We could fix it but nobody gives a shit. Just apathy and BAU.

We really can't fix it. You try and coordinate updates across all major (and most minor, and outdated) OSs, and websites around the world, amateur & professional, from the mom-and-pop store who don't understand any of this, to the big bank that'll take 3 years of procedure.

I have friends who work in the CA field (on the OS side). The level of alcoholism and turnover in the field is... higher than average.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#213

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

Wildcards work on crt.sh:

https://crt.sh/?q=%25.ycombinator.com

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#214
post #39

Earlier quoted context omitted.

Unlike web browsers, digital signature use cases should perform revocation checks, so revoking the google.com certificate should solve that.

I think the current "meta" is CAA records? https://blog.cloudflare.com/why-certificate-pinning-is-outda...

CAA records rely on the CAs to respect them, and this is an article about how a CA has issued a cert in violation of a CAA record.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#215

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

> We could fix it but nobody gives a shit. Just apathy and BAU. We really can't fix it. You try and coordinate updates across all major (and most minor, and outdated) OSs, and websites around the world, amateur & professional, from the mom-and-pop store who don't understand any of this, to the big bank that'll take 3 years of procedure. I have friends who work in the CA field (on the OS side). The level of alcoholism…

Relative to all professions or relative to just IT/tech?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#216

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

crt.sh gives you direct access to their postgres database, if you find the capabilities of their site lacking.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#217

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

> We could fix it but nobody gives a shit. Just apathy and BAU. We really can't fix it. You try and coordinate updates across all major (and most minor, and outdated) OSs, and websites around the world, amateur & professional, from the mom-and-pop store who don't understand any of this, to the big bank that'll take 3 years of procedure. I have friends who work in the CA field (on the OS side). The level of alcoholism…

[deleted]

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#218

Earlier quoted context omitted.

I think the current "meta" is CAA records? https://blog.cloudflare.com/why-certificate-pinning-is-outda...

CAA records rely on the CAs to respect them, and this is an article about how a CA has issued a cert in violation of a CAA record.

Oh right, for some reason I was under the impression that browsers utilize the record too.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#219

Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good." Yeah, this is after the certificate was issued, and my guess, used. Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of th…

How would you fix it?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#220

Earlier quoted context omitted.

Chrome uses the Windows trust store on Windows, IIRC.

I dug a little and apparently Chrome previously used the trust store of the platform but has now transitioned away from that to use their own. https://blog.chromium.org/2022/09/announcing-launch-of-chrom... But even before they switched to this "Chrome Root Program", they have distrusted specific CAs, for example Symantec in 2017. https://security.googleblog.com/2017/09/chromes-plan-to-dist...

Thanks for the info! Didn’t know they moved on.
Post reply on HN