Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

241–250 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#241

Just curiosity: since this report is a Google Doc, how can one know that it has been really written by Mozilla? Shouldn't it be under the mozilla.org domain?

Well, here's the link to the document from the Mozilla Security mailing list: https://groups.google.com/forum/#!topic/mozilla.dev.security...

> Because this document is extensive and contains embedded images, links and formatting, I have published it on Google Docs instead of as an email message here: https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBG...

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#242
post #222

Earlier quoted context omitted.

Same here, I've just recently obtained a "Class 2 Code Signing" certificate from StarCom for digital sign my Windows software - as a individual software developer from China, I don't even have alternative options - I tried purchasing from Comodo, but unfortunately there process for checking individuals from out out of the US is extremely difficult. So I wish this would not affect the certificates StarCom issued for c…

I use (reasonably cheap, using MSDN discount) DigiCert one, and I'm an individual living outside US. Very little hassle involved.

Thanks for the info, will DigiCert once the startcom code singing cert. is no longer relevant on Windows :;

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#243
post #181

Earlier quoted context omitted.

> They're unlikely to survive for a year Well, they might, unless the other browser vendors do the same. Firefox is only like 10% of the total browser market (mobile included).

Browser shares vary wildly by country. For example in germany FF is still the widest used desktop browser. Including mobile probably tips it in favor of safari or chrome, but losing a substantial portion of the desktop market in Europe's largest economy will hurt you.

>> For example in germany FF is still the widest used desktop browser.

Do you have any references to back that up? I'm asking because I suspect your assumption is completely wrong.

(Based on a bunch of analytics data that I have access to, which might not be representative but still contains some very large german web properties, chrome has more than twice the market share compared to FF in germany).

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#244

Earlier quoted context omitted.

Browser shares vary wildly by country. For example in germany FF is still the widest used desktop browser. Including mobile probably tips it in favor of safari or chrome, but losing a substantial portion of the desktop market in Europe's largest economy will hurt you.

>> For example in germany FF is still the widest used desktop browser. Do you have any references to back that up? I'm asking because I suspect your assumption is completely wrong. (Based on a bunch of analytics data that I have access to, which might not be representative but still contains some very large german web properties, chrome has more than twice the market share compared to FF in germany).

Not sure how accurate it is but this shows that FF is still the first desktop browser (but not for long it seems) in Germany:

http://gs.statcounter.com/#browser-DE-monthly-201508-201608

On the other hand if you only look at mobile, Chrome is well ahead of everything else:

http://gs.statcounter.com/#mobile_browser-DE-monthly-201508-...

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#245
post #95

Earlier quoted context omitted.

My hope would be that since this method of punishing seems to be liked by most and even feels "generous" to some, the browser vendors would more aggressively start handing out "1 year suspensions" for more and more CAs that are caught doing anything even remotely like this. Then after a year or two, and after the CAs have learned that they need to take this stuff seriously, and yet some still get caught doing it, the…

The people saying this is "generous" are making largely irrational arguments. What Mozilla is proposing is the worst case for incumbent CAs.

While it will stop new customers, maybe they can keep extising by issuing them now certificates valid for 2 years.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#246
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

StartCom/WoSign/Qihoo360 are killing their own CA. You can't keep lying and expect people to trust you, eventually the truth will catch up with you. Cry me a river.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#247
post #23
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

after their heartbleed extortions they really deserve nothing less (and yes, I was a paying customer)

While their current/recent behaviours that are being discussed are deplorable, I don't think the heartbleed thing is as morally corrupt as many people affected make out.

Their rules always clearly stated the cost of replacement certificates and that this would only be waived if the replacement was needed due to their fault. As heartbleed was not a problem they caused they were well within their agreements with the customers to charge for revoking and resigning certificates.

They missed a chance at earning "good faith points" but they presumably didn't value that over the income from resigned certificates. They are a commercial body afterall.

Lets not dilute the discussion of cases where they appear to have been deliberately fraudulent by mixing in a past occurrence of them simply being uncaring.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#248
post #220
post #210

Earlier quoted context omitted.

Doesn't the CA have one move left in this game of brinkmanship? They can start brazenly backdating their new certificates to fall into the accepted window, which would leave us right back at holding their own customer base hostage.

This is addressed in the document as well: WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. However, many eyes are on the Web PKI and if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots. If the CA really goes that…

Right, and that's fine and good for WoSign/StartCom. But what if they handed out a one year restriction to a much larger CA like Comodo, or Symantec? And that CA decided to back-date their certificates? Then we still have the problem of large CAs being able to effectively ignore these restrictions because of their large userbase. As long as such CAs are able to set the notbefore arbitrarily, they can backdate as much as they'd like.

The only solution I can think of is to have some kind of giant database of all certificates seen in the wild that were issued by said CA, and not trust any new ones. (This may be something that can be done with Certificate Transparency, but I haven't read enough on that to be sure.) This would allow Mozilla/Apple/Microsoft to actually block new certificates.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#249
post #205
post #121

Earlier quoted context omitted.

What use case do you have for wildcards that you can't use Let's Encrypt or similar automated issuance? Just curious, as I've yet to hear a terribly compelling one...

Not the parent, but wildcard certs are necessary for compatibility with clients that don't support SNI (ex: IE on WinXP)

No. You could also issue SubjectAltName certificates. Works fine with XP.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#250

Earlier quoted context omitted.

>In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed Given the risks that screwups have to their business, I would think CAs would VOLUNTARILY do this.

Giggle. Look at Diebold's numerous malfeasance issues in ATM and voting industries. If anything, they have much more to lose by voluntary audit. Unsavory CA's might well be in the same position.

Can you elaborate? I am not familiar with the specifics of Diebold's problems and how a voluntary audit (which they could choose to keep private and use for internal assessment) would hurt them more than not knowing the risks.
Post reply on HN