Live data from Hacker News

Remediation Plan for WoSign and StartCom

groups.google.com

31–40 of 54 posts

Re: Remediation Plan for WoSign and StartCom

#31
post #11
post #8

Just curious about the root certificate distrust--are users capable of re-adding trust to distrusted certificates? Or is this hard coded into the browser? I'm assuming Mozilla stores certificates outside OS stores like Keychain and Windows?

Yes but why would you? If you have control of all your clients to push such a change, why not just set up a private CA instead of opening yourself up to the whims of a proven cheating CA?

Less difficult. Setting up a private CA means you have to be the CA, and vet and/or create a cert for every wosign/startcom site that people visit. One could trust them just enough depending on how heavily they depend on affected sites. I personally would rather whitelist sites as-needed, but can see why some admins would go the easier route.

Re: Remediation Plan for WoSign and StartCom

#32

What did I miss? Last I heard about this, the plan was to ban them from issuing new certificates for a year. Did something change?

They admitted they screwed up and the CEO stepped down.

"Will step down", according to his own post on https://groups.google.com/d/msg/mozilla.dev.security.policy/....

Re: Remediation Plan for WoSign and StartCom

#33
post #11

Earlier quoted context omitted.

Yes but why would you? If you have control of all your clients to push such a change, why not just set up a private CA instead of opening yourself up to the whims of a proven cheating CA?

Less difficult. Setting up a private CA means you have to be the CA, and vet and/or create a cert for every wosign/startcom site that people visit. One could trust them just enough depending on how heavily they depend on affected sites. I personally would rather whitelist sites as-needed, but can see why some admins would go the easier route.

Existing certs will continue to work until they expire. So "re-adding trust" to WoSign doesn't make sense. No sane site operator would renew their cert with WoSign since they will lose all Firefox and Apple clients.

Re: Remediation Plan for WoSign and StartCom

#34
post #19

What did I miss? Last I heard about this, the plan was to ban them from issuing new certificates for a year. Did something change?

That remains the plan.

> 1) Distrust certificates chaining up to Affected Roots with a notBefore date after October 21, 2016.

> ...

> 4) Remove the Affected Roots from NSS after the SSL certificates issued before October 1, 2016, have expired or have been replaced.

This sounds more serious than that. It says they can re-apply for inclusion of new roots next June though. So in practice it might really be just a one-year ban, if they will apply and pass the inclusion process.

Re: Remediation Plan for WoSign and StartCom

#35
post #33

Earlier quoted context omitted.

Less difficult. Setting up a private CA means you have to be the CA, and vet and/or create a cert for every wosign/startcom site that people visit. One could trust them just enough depending on how heavily they depend on affected sites. I personally would rather whitelist sites as-needed, but can see why some admins would go the easier route.

Existing certs will continue to work until they expire. So "re-adding trust" to WoSign doesn't make sense. No sane site operator would renew their cert with WoSign since they will lose all Firefox and Apple clients.

I wasn't saying it was a sane way to do it, just the easiest. I could also see it turning into a nationalism issue -- "The West is unfairly attacking native CAs." -- as impetus to try to convince people to manually trust and/or renew certs with them.

Re: Remediation Plan for WoSign and StartCom

#36
post #23

I am glad this is happening. I have lost all trust in StartCom when they blatantly ignored the issues surrounding Heartbleed, refusing to renew certificates, despite every other CA doing so. I hope their learn their lesson, and try to be more honest in the future!

Small nitpick: StartCom refused to revoke certificates at the time, not renew them.

Re: Remediation Plan for WoSign and StartCom

#40
post #20

I dont like this route. The only value for the WoSign keys for a whole year would be issuing certificates with a doctored notBefore date, and they can't do that publically.

They could start reselling certs from a CA. That way their customers wouldn't have to sign up with a different CA. Then a year later, they could get everything back to normal.
Post reply on HN