Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

231–240 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#231

Earlier quoted context omitted.

No, it is pretty well established that countries have corruption problems, and cultural attitudes can be at variance to what you would expect. Many practices we would find outragously corrupt are common in China, with no recourse through the legal system. https://www.transparency.org/country/#CHN

That's a tautology. "cultural attitudes can be at variance to what you would expect" anywhere.

Not really, you could refute it by showing that cultural attitudes are the same everywhere. It is simply stating that across 1.5B people there is no certainty that a cultural assumption (especially from an occidental viewpoint) should hold.

I should perhaps backtrack to emphasize that HK generally has much greater transparency and adherence to law than mainland China, and I would have no hesitation is choosing a HK firm to do work. I just think they had inexperienced people and stuffed up.

Great mainland Chinese concept to study: xiaojinku, little company slush funds for rewards, gifts, making and receiving bribes, and rainy days. All part of guanxi.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#232

I think Mozilla is falling for Symantecs / other CAs propaganda here. Yes, WoSign did bad things, but those are by far not the worst things we've seen in CA wrongdoings in the last years. We've seen certs issued for MITM attacks and security holes in the validation process of nearly every CA. ( http://www.theregister.co.uk/2012/02/14/trustwave_analysis/ ) Bottom line: "Let's encrypt" is destroying the business of man…

There were a number of other issues that came up during this investigation that showed that they should not be running a CA[1]. For example, they issued certificates to anyone able to control a unprivileged port (> 1024) behind a domain. They issued certificates for "root domains" to anyone able to verify control of a subdomain. When StartCom launched their issuance API, it was taken down within a matter of days due to some pretty obvious holes.

The biggest problem with the SHA-1 issuance is that they - as the report shows - blatantly lied about how this played out during the investigation and did not even attempt to go through the proper channels to get an exception from browser vendors (which other CAs did). Additionally, issuing a SHA-1 certificate to a payment processor that failed to upgrade their systems in time cannot be explained by China having a large number of XP Regarding the TrustWave incident a few years back, it's important to understand that this happened when the rules for CAs were not quite as clear as they are now. I think this happened just around the time when the Baseline Requirements were written and were not yet in effect, and various browser policies were not as clear as they could've been about this use-case. Four years later, I have no doubts that a CA who'd give out the private key of a non-constrained CA certificate to a non-audited third-party would lose their trust status within a matter of days.

[1]: https://wiki.mozilla.org/CA:WoSign_Issues

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#234
post #118

Earlier quoted context omitted.

OK, so what do you want to happen starting tomorrow morning? * All HTTPS sites show up as trusted. Woohoo! * All HTTPS sites show up as untrusted, people are encouraged to switch to HTTP. Woohoo! * All HTTPS sites use trust-on-first-use, which means that we have a date and time announced when MITM attacks are particularly effective and will persist for a very long time. * All HTTPS sites are untrusted, except for tho…

#3, with HKPK and a transition period covered by CAs, is not entirely unreasonable and even offers some real advantages. The changeover doesn't need to take place at the stroke of midnight.

You could engineer #3 to work, but the big trouble is that occasionally someone will reinstall their web server from scratch (on purpose or as part of disaster recovery), lose the key, and expect not to lose their website permanently. I have yet to see any organization that deals usefully with changed SSH keys and communicates them properly instead of "oh yeah, we changed that, delete it from known_hosts and it'll be fine", and organizations that use SSH are more likely to know what they're doing than the average Internet site (in fact I count MIT's CS department as one of the guilty parties). An internet-wide equivalent of "yeah, just delete example.com from your known_hosts" is essentially an internet-wide announcement of "yeah, plz start MITMing example.com".

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#235
post #128

Earlier quoted context omitted.

> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…

Really, either way, this is a death sentence for Wosign/Startcom. They're unlikely to survive for a year + all of the time and cost it would take to recertify without any revenue from certificate issuance. Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it wou…

There's no guarantee their suspension will only last a year.

They have to go through the normal Mozilla inclusion process and a bunch of extra hoops to get re-trusted. I think you're calling them walking dead pretty well nails it. Their smartest move right now might be to close up shop and walk away.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#236
post #13

>We also hope the public can see that when there are allegations of CA wrongdoing, Mozilla is committed to a fair, transparent and thorough investigation of the facts of each case. I'm very happy to see the way Mozilla handled this incident, both with the process and the conclusion. I have a moderate trust in the CA ecosystem as a whole, but I'm glad to see that overwhelming incompetence, if not outright maliciousnes…

>In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed Given the risks that screwups have to their business, I would think CAs would VOLUNTARILY do this.

Giggle.

Look at Diebold's numerous malfeasance issues in ATM and voting industries. If anything, they have much more to lose by voluntary audit.

Unsavory CA's might well be in the same position.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#237
post #11

I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?

When the story first broke, I manually untrusted WoSign's and StartCom's root certificates in OS X, instead of deleting them outright...at least I thought I did. I upgraded to macOS 10.12 Sierra this past weekend, and repeated the process. Except WoSign's certificates aren't there to begin with, though StartCom's still are. So perhaps Apple had dropped WoSign already? Would anyone else running 10.12 verify?

Possibly it is an intermediate certificate that is not cached yet. Does https://www.wosign.com/ give you a certificate error, and does the certificate appear in the list after visiting the site?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#238
post #232

I think Mozilla is falling for Symantecs / other CAs propaganda here. Yes, WoSign did bad things, but those are by far not the worst things we've seen in CA wrongdoings in the last years. We've seen certs issued for MITM attacks and security holes in the validation process of nearly every CA. ( http://www.theregister.co.uk/2012/02/14/trustwave_analysis/ ) Bottom line: "Let's encrypt" is destroying the business of man…

There were a number of other issues that came up during this investigation that showed that they should not be running a CA[1]. For example, they issued certificates to anyone able to control a unprivileged port (> 1024) behind a domain. They issued certificates for "root domains" to anyone able to verify control of a subdomain. When StartCom launched their issuance API, it was taken down within a matter of days due…

> issuing a SHA-1 certificate to a payment processor that failed to upgrade their systems in time

Its ok, its just a temp workaround... /s - https://tyro.com/blog/merchant-security-is-tyros-priority/

Tyro don't say when they got their SHA-1 cert from StartCom but say they needed this workaround because some of their customers still ran POS software on old operating systems such as Windows XPSP2 and that "internet security standards are moving faster than typical small merchants upgrade their systems."

> "We reached out in good faith to certificate authorities to provide a few months runway to resolve this big challenge in a way that had minimal impact on merchants."...

To me this would be ringing so many alarm bells, why would my current CA tell me they can not issue a SHA-1 cert but StartCom say they can? (I believe they got issued the SHA-1 cert after the cutoff because of the details in the document Mozilla have supplied and that we are no longer a few months into 2016 so their need for a "few months runway" was way off) Yes it would mean my customers POS systems would still function but I'm sure as hell would be asking questions about its issuance.

EDIT: Tyro have removed their StartCom SHA-1 cert from https://iclient.tyro.com/ and its now supplying a RapidSSL cert issued in May of this year but yesterday they were serving a StartCom SHA-1 cert on their iclient subdomain.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#239

Earlier quoted context omitted.

I am having a really hard time following this argument. The CA isn't vouching for the content of your HTTPS requests.

No, the only thing the CA vouches for is that the other party is who they claim to be, which 99% of the time doesn't matter because I don't trust who they claim to be any more than I trust someone impersonating who they claim to be.

How can the CA be _more_ trustworthy as to whether the other party is really Bank of America... than Bank of America itself is?

I don't understand your argument, and I think it's a novel interpretation of the CA infrastruture, I think whatever threats you are considering (that Bank of America would intentionally lie about what website is a Bank of America website?) is not something the CA infrastructure was designed to protect against or is capable of protecting against.

If authorized Bank of America staff is committed to claiming some website is Bank of America, they can get it trusted as Bank of America by a third-party CA too, can't they? I think by definition any website that authorized Bank of America agents claim is a Bank of America website, _is_ a Bank of America website. That's all it means to be "really" a BoA website, to be a website BoA intentionally meant to represent BoA.

I don't think the CA infrastructure can possibly defend against authorized Bank of America agents claiming a website is a BoA website when you think they were wrong to claim that. The CA infrastructure is meant to guarantee that the website was intentionally authorized by Bank of America to be a Bank of America website -- that's it. It doesn't even always do that securely because of flaws, but it never does any more than that.

Am I missing something?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#240

Earlier quoted context omitted.

I'd be very interested to know which of the EFF's political positions you object to, but it appears pretty clear you're avoiding answering that question...

I don't see how that's relevant, unless the goal is to invalidate his(?) dislike of them by claiming the political views that dislike is based on are wrong and stupid.

The goal was to find out more. Having never encountered an anti-EFF person on here (or anywhere, that I can recall) I was interested in the answer.
Post reply on HN