Live data from Hacker News

Apple's response to the WoSign incidents

groups.google.com

31–39 of 39 posts

Re: Apple's response to the WoSign incidents

#31

Earlier quoted context omitted.

> There's literally no way we could afford to pay for new certs from an alternative registrar instead. If ~$100 is that much for you (as a company of some sort) why don't you use Letsencrypt?

Good point, that might be the better solution for the public HTTPS part of things. Lets Encrypt doesn't provide MS Authenticode signing certs (eg to validate our downloads are legit) though. Hopefully this whole mess doesn't scope creep to include those too.

You bet it will. If MS does not revoke them, it will reflect very badly on the security of their program.

Re: Apple's response to the WoSign incidents

#32
post #4

Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate. 2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this. 3. Mozilla proposed dis-trusting all new WoSign/StartCom certific…

For those who may not remember or may not have heard, QiHoo is the company behind the most popular scam browsers in the world: Qihoo 360 Secure. It was one of the most popular browsers in China with 28% of the market a few years ago. It used an IE logo colored green, force-uninstalled competing browsers by claiming they were unsafe, made uninstallation so difficult you'd often have to re-image the machine, breaks SSL…

Also the sixth browser vendor in the CAB forum.

Re: Apple's response to the WoSign incidents

#33
post #16

Sorry if this is obvious to others, but just to be clear ... As it's widely reported that WoSign has taken over StartCom's infrastructure, this implies that StartCom StartSSL Free certificates going forward won't be trusted by Apple either, correct? It also sounds a little strange to only call out the free certificates. Are they going to allow new paid OV/EV (and what they call 'IV') certificates to remain valid?

There are plenty of other ways to get a free certificate, e.g.

Let's Encrypt

AWS Certificate Manager

cPanel's AutoSSL

CloudFlare

Symantec Encryption Everywhere

Not to mention the certificates that can be bought very cheaply through resellers e.g. PositiveSSL.

Re: Apple's response to the WoSign incidents

#34

Earlier quoted context omitted.

Good point, that might be the better solution for the public HTTPS part of things. Lets Encrypt doesn't provide MS Authenticode signing certs (eg to validate our downloads are legit) though. Hopefully this whole mess doesn't scope creep to include those too.

You bet it will. If MS does not revoke them, it will reflect very badly on the security of their program.

If anything, I'd expect code signing certificates to be at more risk. Usage of these certificates is inherently much more difficult to track, as signed executables are much harder to discover than web servers. As such, even if there were a "certificate transparency" process for code signing certificates (which I don't believe there is), it'd be difficult to prove it was being operated honestly.

Re: Apple's response to the WoSign incidents

#35
post #28

Earlier quoted context omitted.

Ugh. September 19th is poor date to choose. When this came up, the first thing I did was generate wildcard certs for our StartCom domains, as Mozilla is going to stop trusting things at some point. But that was on ~26th September. Choosing the 19th is giving existing customers of StartCom no chance to manage the problem in a sensible way. :(

This announcement only pertains to the "WoSign CA Free SSL Certificate G2" intermediate CA and does not affect any StartCom-issued certificates. They might announce similar steps for StartCom in the future, but nothing as of yet.

Thanks. Glad I misunderstood it. :)

Hopefully if it expands to include StartCom certs, they use a later date.

Re: Apple's response to the WoSign incidents

#36
The John Ringo approach, from "Citadel". A Chinese supplier cut corners on the gold plating of a contact and caused a major accident. The response:

"The supplier, Qua Tang Electronics, is blacklisted. Find every person associated, every member of the board, every senior officer, and blacklist any company they are associated with as well. With something like this, and the Chinese, there is no overkill. Be wildly unaimed in your fire. Nuke first, ask questions afterward. Make the pain as widespread as possible."

Re: Apple's response to the WoSign incidents

#38
post #15

Earlier quoted context omitted.

For those who may not remember or may not have heard, QiHoo is the company behind the most popular scam browsers in the world: Qihoo 360 Secure. It was one of the most popular browsers in China with 28% of the market a few years ago. It used an IE logo colored green, force-uninstalled competing browsers by claiming they were unsafe, made uninstallation so difficult you'd often have to re-image the machine, breaks SSL…

And yet, unless you go through the effort of removing every trusted CA from your browser, you implicitly trust them because Mozilla/Google/etc. do. And thus why the CA system is broken in a nutshell.

>And thus why the CA system is broken in a nutshell.

I wouldn't call it broken. From what I see on Linux and Windows, Chrom[e|ium] relies on the system's trusted certificates. You always have the last says on who's in and who's out.

EDIT: Just checked, the Chromium-specific trusted CAs can be revoked through its configuration interface, doesn't just rely on system certs. Important detail, but still, user has the last word.

Re: Apple's response to the WoSign incidents

#39

Earlier quoted context omitted.

When this came up, the first thing I did was generate wildcard certs for our StartCom domains A vendor you used comes under scrutiny so your response is to double down on them? Did you have prepaid credits or something? It seems like that would have been a opportune time to migrate away from them since you'd have to redeploy certs anyways.

With StartCom, once you've gone through the personal verification procedure you don't need to pay more money for new certs, nor wildcard ones. So, no "doubling down" involved. Just a desire to have actually working certs before Mozilla's "to be announced" cut off date happens. And then Apple comes along and (unless I'm misunderstanding) all of our certs will be useless. :(

> So, no "doubling down" involved

Continuing to use a CA that has a recognised history of fucking abysmal security and wilfully deceptive actions, whether you're paying money or not, is still "doubling down" IMO.

If you're getting a wildcard cert, you aren't getting EV, so why not just make the switch to LetsEncrypt?

Post reply on HN