Live data from Hacker News

Actalis: Insufficient Serial Number Entropy

bugzilla.mozilla.org

31–34 of 34 posts

Re: Actalis: Insufficient Serial Number Entropy

#31

Could somebody explain to me why Mozilla (or whatever organisation is using bugzilla here) are in a position to dictate policy here? If the majority of outstanding certificates were held by the Italian government, major banks and hospitals, what are the CA supposed to do if they're just told "No, you won't revoke the certificates until we're ready, we don't think the risk is worth it"? Further, reading a comment belo…

Somebody has to decide who is trusted. Mozilla (a not-for-profit) thinks that it suits their mission best if they're deciding, at least when it comes to their browser, Firefox, by default. If you think somebody else should decide - maybe the Government of Italy, or the Queen of England, or Donald Trump, or you personally, then here's a few questions for your new Root Trust Programme: 1. Why? At least Mozilla's ration…

I'm not saying Mozilla isn't a good organisation to run this, I'm saying it seems insane to have what seems like policies that don't allow for any proportional response.

I don't know how involved you are, but to a lay observer this story seems like Mozilla's policies are entirely black and white, to the benefit of nobody (except perhaps to reduce work I suppose, which is reasonable, but not really a valid reason in terms of security)

Is there no tiered approach to risks? Hell, in this situation it seems like more harm and risk will have been created by the rush to reissue certificates that would have been caused by this theoretical security vulnerability.

Edit: Actually, on further reading, it seems like the issue is more that Actalis didn't correctly invoke their right to this discretionary power?

Re: Actalis: Insufficient Serial Number Entropy

#32

Earlier quoted context omitted.

Somebody has to decide who is trusted. Mozilla (a not-for-profit) thinks that it suits their mission best if they're deciding, at least when it comes to their browser, Firefox, by default. If you think somebody else should decide - maybe the Government of Italy, or the Queen of England, or Donald Trump, or you personally, then here's a few questions for your new Root Trust Programme: 1. Why? At least Mozilla's ration…

I'm not saying Mozilla isn't a good organisation to run this, I'm saying it seems insane to have what seems like policies that don't allow for any proportional response. I don't know how involved you are, but to a lay observer this story seems like Mozilla's policies are entirely black and white, to the benefit of nobody (except perhaps to reduce work I suppose, which is reasonable, but not really a valid reason in t…

You may also enjoy https://wiki.mozilla.org/CA/Incident_Dashboard , which all the CAs responding to such incidents need to be aware of, and which shows that there is a rather large amount of proportionality, based on an appropriate degree of transparency and communication.

Re: Actalis: Insufficient Serial Number Entropy

#33
post #32

Earlier quoted context omitted.

I'm not saying Mozilla isn't a good organisation to run this, I'm saying it seems insane to have what seems like policies that don't allow for any proportional response. I don't know how involved you are, but to a lay observer this story seems like Mozilla's policies are entirely black and white, to the benefit of nobody (except perhaps to reduce work I suppose, which is reasonable, but not really a valid reason in t…

You may also enjoy https://wiki.mozilla.org/CA/Incident_Dashboard , which all the CAs responding to such incidents need to be aware of, and which shows that there is a rather large amount of proportionality, based on an appropriate degree of transparency and communication.

That is very interesting, thank you. And yes, the tone and approach in all the incidents I read through there seemed great.

Re: Actalis: Insufficient Serial Number Entropy

#34

I kind of feel for Actalis. It seems like they were caught between a rock and a hard place seeing as their customers were not/could not respond as quickly as hoped and revoking the certs could negatively impact end-users by preventing them from for example obtaining prescriptions etc. The language is dense for me but it also sounded like there was a reasonable explanation in the BR for the exception (paraphrasing: ‘n…

From my limited POV, this seems like collateral damage from overblowing the trivial bug they used to beat the DarkMatter CA over the head.

I didn’t find the arguments of severity convincing then either. But the gist was that they need to be completely consistent and rigorous so it does make sense even if it is a massive inconvenience for people. Again.

Post reply on HN