Earlier quoted context omitted.
Wosign is not in the list of default CAs on the Mac, according to Keychain, so if you are using Chrome on a Mac, since Chrome only uses the system's root certs, you should be safe as long as you don't go add that root cert into Keychain. Wosign is in Firefox however, so Mozilla needs to do something about this.
They're cross-signed by StartCom, which is trusted by MacOS.
Chinese CA WoSign faces revocation after possibly issuing fake certificates
31–40 of 116 posts
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#32If a CA pulls shit like this they need to be revoked immediately and let the wrath of 1000s of businesses that are impacted by cert warnings rain down upon them. That will 1) Solve the security problem immediately and 2) Publicize what it means to get a cert from a crap CA that doesn't care about security.
Sure it will suck for the "little guy" who didn't know but, if you don't do this, he'll never know and never learn.
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#33Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#34Earlier quoted context omitted.
That's exactly the internet equivalent of too big to fail banks. And like for banks it is unacceptable. The internet needs its Lehman moment to become resilient again. We should let a Comodo fail.
So what is the solution to big banks and big CAs? We are just in the process of collectively creating the biggest CA the world ha sver seen.
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#35I just went to delete these roots from my Windows system but it's not listed. It was in Firefox's list but not in Window's. Anyone know why?
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#36Earlier quoted context omitted.
It would certainly be better than nothing, yes. But prior to March 2015, CAs could issue certs valid for up to 5 years. So even if browsers stopped accepting WoSign certs with an issuance date after today, WoSign could still issue certs "issued March 2015 valid until to March 2020" and browsers would accept them.
If they start putting fake dates on the certs then the nuclear option is the only option. They are in the business of selling trust and they're outright lying on their only product? That's untenable.
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#37Is there an easy way for me to revoke trust from all Chinese CAs? Anyone in China is ultimately subject to being forced to do the dirty work of the Chinese Communist Party. Why are browser and OS vendors even trusting them in the first place?
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#38Too big to fail my ass. There's no such thing when it comes to security. If anything, that's more reason to cut them loose. If a CA pulls shit like this they need to be revoked immediately and let the wrath of 1000s of businesses that are impacted by cert warnings rain down upon them. That will 1) Solve the security problem immediately and 2) Publicize what it means to get a cert from a crap CA that doesn't care abou…
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#39Earlier quoted context omitted.
That's exactly the internet equivalent of too big to fail banks. And like for banks it is unacceptable. The internet needs its Lehman moment to become resilient again. We should let a Comodo fail.
So what is the solution to big banks and big CAs? We are just in the process of collectively creating the biggest CA the world ha sver seen.
The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, more importantly, for warnings to not display) in users' browsers. That's it; beyond that it's a race to the bottom on price.
If a few CAs went down in flames and in doing so created a nasty firedrill for all their customers (which, on the scale of firedrills, getting new certs issued really shouldn't be that big of a deal, compared to a zero-day vulnerability in some piece of the server stack, which happens fairly regularly), suddenly there might be an interest in acquiring certificates from somewhere other than the cheapest-possible source.
Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates
#40I just went to delete these roots from my Windows system but it's not listed. It was in Firefox's list but not in Window's. Anyone know why?
They're cross-signed by startcom.
Friendly names: WoSign - WoSign 1999 - WoSign ECC - WoSign G2 - WoSign China