Earlier quoted context omitted.
> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…
Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…
WoSign and StartCom: Mozilla’s proposed conclusion
221–230 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#222Earlier quoted context omitted.
One problem - at least for the project I'm working on - is that Lets Encrypt isn't a replacement for all of StartCom. We use a StartCom "MS Authenticode" certificate to sign our releases, so Windows users don't get a warning message from the various anti-malware scanners (and similar). At first glance it sounds like Mozilla not accepting new StartCom cert's at some point won't affect that. It may snowball, but that's…
Same here, I've just recently obtained a "Class 2 Code Signing" certificate from StarCom for digital sign my Windows software - as a individual software developer from China, I don't even have alternative options - I tried purchasing from Comodo, but unfortunately there process for checking individuals from out out of the US is extremely difficult. So I wish this would not affect the certificates StarCom issued for c…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#223>We also hope the public can see that when there are allegations of CA wrongdoing, Mozilla is committed to a fair, transparent and thorough investigation of the facts of each case. I'm very happy to see the way Mozilla handled this incident, both with the process and the conclusion. I have a moderate trust in the CA ecosystem as a whole, but I'm glad to see that overwhelming incompetence, if not outright maliciousnes…
>In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed Given the risks that screwups have to their business, I would think CAs would VOLUNTARILY do this.
Nothing illustrates it better than @tux3 above: "I have a moderate trust in the CA ecosystem as a whole"
Trust in CA's is a bit like trusting your bank or state. Only that if you trust one bank you automatically trust all banks (unless you use key-pinning or other on top solutions that have been bolted-on afterwards).
CAs have a license to print money. What we need is a transparent Authority that is owned by the people not by some megacorp which not only issues sites but individual identity certificates. It's important to know if the CA have "Skin in the game" when they say they can protect you. (none of them do).
Disclosure: I work for The Authenticity Institute and we're quite active in that domain (also we think the way CAs are managed is a liability in the age of critical IIoT and ICS security).
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#224I'm not going to defend WoSign/StartCom's shady tactics, but the way the deprecation of SHA1 was performed puts people in a pretty shitty position. You can't support Windows XP users who use IE anymore with HTTPs. In the western world, that number is very small. It's around 1% still using XP and most of those people are probably not using IE anymore. In china though, that number is still >5%, and I got that number pe…
> You can't support Windows XP users who use IE anymore with HTTPs. Sure you can. Just ask a CA that has an old root trusted by XP but no longer trusted by modern browsers, and they'll issue a SHA-1 cert for you without risking to get kicked out of the truststores.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#225Earlier quoted context omitted.
CAs need irreproachable reputations, anything less is absurd, like trusting your bank manager even though you know they have a gambling problem and owe money to Fat Tony. Having sympathy for their commercial corcerns is absurd. The better solution would be to alert on all of their certs as being 'low trust'. A first step towards explicit trust belief , where reputations build slowly over time and can be severly damag…
How is that solution better than effectively putting them out of business?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#226While I agree that they did the wrong thing and WoSign/StartCom should be punished for lying, the whole sha-1 deprecation thing is very black and white. Others have successfully gained "exemptions" to do precisely this, and it's an interesting question whether it would have been easy for WoSign to get those same exemptions if they'd just asked. I bet the answer is "possible but not easy". Meanwhile: http://security.s…
I would bet the same. This seems like what you want for an exemption process: if it's too easy, people will use exemptions rather than fixing an underlying problem.
> someone's personal blog needs to have the same level of security as the apple app store's payment system
Different grades of security would not have helped in this case, because it was payment systems having trouble updating, and we put anything involving money on a high security tier - except when legacy systems get an exception.
It's not quite one-size-fits-all, because EV certificates are meant to show more trust, and most banks etc. will use those. That takes extra work, which isn't worth it for a personal site. But you don't save any work by using a weaker hash algorithm, so there's no reason for a personal blog to do so.
> the CAB chose to inflict a ton of pain and cause still-functioning hardware to be discarded
It does sound like they should have had an exemption process set up before the cutoff date, or put the cutoff further out to give people more time to upgrade systems. But using Hanlon's razor, it was probably an oversight rather than deliberate 'environmental vandalism'.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#227Earlier quoted context omitted.
Really, either way, this is a death sentence for Wosign/Startcom. They're unlikely to survive for a year + all of the time and cost it would take to recertify without any revenue from certificate issuance. Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it wou…
> They're unlikely to survive for a year Well, they might, unless the other browser vendors do the same. Firefox is only like 10% of the total browser market (mobile included).
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#228While I agree that they did the wrong thing and WoSign/StartCom should be punished for lying, the whole sha-1 deprecation thing is very black and white. Others have successfully gained "exemptions" to do precisely this, and it's an interesting question whether it would have been easy for WoSign to get those same exemptions if they'd just asked. I bet the answer is "possible but not easy". Meanwhile: http://security.s…
Issuing a SHA-1 certificate for one domain doesn't just put that domain at risk, it threatens the entire ecosystem. Someone requesting such a cert may have a second cert with the same hash, but for a different domain or even an intermediate, like the MD5 collision. It's not like you could avoid this by asking "are you a nation state attacker" during the application process.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#229Earlier quoted context omitted.
> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…
> it's annoying for customers, but they just have to subscribe to a new CA and install the new cert Well I would be a little more embarrassed than that, because Wosign/Starcom were the only ones offering free SSL certificates for international domain names. So there's no way I would pay for SSL certificates for my various personal projects and websites, but then I just couldn't get valid certificates for them anymore…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#230Earlier quoted context omitted.
Surely you could have demanded a refund if you had chosen StartSSL and they sold you what turned out to be a defective product?
Good luck collecting after the company's potential future revenue has been erased.
The trickier part is, it's unknown whether StartCom will backdate more certificates, triggering Mozilla to block them entirely. That could happen well after the window where you're allowed to request a chargeback. Although I do believe it's extremely unlikely that they will. Unless Google and Microsoft follow suit, such an action is just as likely to damage Mozilla as it is to damage StartCom. People who just want to access websites will not bother to understand the reason why suddenly only Firefox is refusing to let them view their pages.