Live data from Hacker News

Entrust Certificate Distrust

security.googleblog.com

31–40 of 118 posts

Re: Entrust Certificate Distrust

#31
post #20

Earlier quoted context omitted.

As long as the victims are checking it and know what to look for!

Chrom(e/ium) and Safari don't trust certificates that are not in public logs [0]. [0] https://en.wikipedia.org/wiki/Certificate_Transparency#Manda...

Right, and that's a fundamental sea change in PKI security posture since the Iranian "ComodoHacker" and the Soghoian and Stamm compelled issuance paper! My point is just that some attackers might be willing to have their attacks show up in public logs if their victims are unlikely to ever notice that and if nobody else is likely to notice it either.

With Let's Encrypt we made a lot of people's certificate management a "fire and forget" thing, which is exactly what we hoped to do, but if they completely forget about it, it may be that there will be lots of targets against whom nobody would notice certificate misissuance.

Re: Entrust Certificate Distrust

#33
post #28

Earlier quoted context omitted.

api.cybersource.com This is gonna cause me some headaches, along with everyone else who processes payments through Cybersource, and possibly others :(

CYBS Engineer here. We're already working on it. Keep an eye for merchant notifications if you use certificate pinning. Now, back to rotating certificates....

Out of curiosity, is your organization planning to switch to Let's Encrypt or just another year long certificate provider?

It'll be interesting to see what, if any, organizations affected by this switch to: Stick with 1 YR certs or go to the future with free 90 days?

Re: Entrust Certificate Distrust

#34
post #31

Earlier quoted context omitted.

Chrom(e/ium) and Safari don't trust certificates that are not in public logs [0]. [0] https://en.wikipedia.org/wiki/Certificate_Transparency#Manda...

Right, and that's a fundamental sea change in PKI security posture since the Iranian "ComodoHacker" and the Soghoian and Stamm compelled issuance paper! My point is just that some attackers might be willing to have their attacks show up in public logs if their victims are unlikely to ever notice that and if nobody else is likely to notice it either. With Let's Encrypt we made a lot of people's certificate management…

The other argument is, why bother MITMing when you can go to Cloudflare and get them to share the data with you :)

Re: Entrust Certificate Distrust

#35
post #20

Earlier quoted context omitted.

As long as the victims are checking it and know what to look for!

Chrom(e/ium) and Safari don't trust certificates that are not in public logs [0]. [0] https://en.wikipedia.org/wiki/Certificate_Transparency#Manda...

Not just Safari, but all TLS connections instantiated on Apple OSes

Re: Entrust Certificate Distrust

#36
> This approach attempts to minimize disruption to existing subscribers using a recently announced Chrome feature to remove default trust based on the SCTs (signed certificate timestamps) in certificates.

I was wondering how Chrome was able to revoke a certificate based on time without trusting the CA to not back date certificates and it looks like this is due to being able to trust certificate transparency logs instead. This is where they get the signed certificate timestamps (SCT) from.

See also https://certificate.transparency.dev/howctworks/

Re: Entrust Certificate Distrust

#37
post #27

It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?

They genuinely believe they are "too big to fail". They've got thousands of employees, they've been around for 30 years, they are a critical part of public infrastructure: surely something as trivial as a few weirdos in a mailing list couldn't instantly kill their entire business? Stuff like this happens when upper management has zero clue about the business they are in. They believe they are in the business of selli…

Perhaps they've decided to draw inspiration from https://bugzilla.mozilla.org/show_bug.cgi?id=647959.

Re: Entrust Certificate Distrust

#38
post #28

Earlier quoted context omitted.

api.cybersource.com This is gonna cause me some headaches, along with everyone else who processes payments through Cybersource, and possibly others :(

CYBS Engineer here. We're already working on it. Keep an eye for merchant notifications if you use certificate pinning. Now, back to rotating certificates....

[flagged]

Re: Entrust Certificate Distrust

#39

> This approach attempts to minimize disruption to existing subscribers using a recently announced Chrome feature to remove default trust based on the SCTs (signed certificate timestamps) in certificates. I was wondering how Chrome was able to revoke a certificate based on time without trusting the CA to not back date certificates and it looks like this is due to being able to trust certificate transparency logs inst…

This kind of thing was one of the reasons CT was introduced :D

Re: Entrust Certificate Distrust

#40
post #15

I’m one of the people who really went in depth with Entrust (Amir on Bugzilla). I’m also an author on https://webpki.substack.com . I will be writing my thoughts on the distrust soon. I can try to answer any questions folks may have. I can also help folks find ways they can also be involved! Root programs can only do so much and need surveillance of the CAs from the community.

I am a layperson so I appreciate the attention on the matter.

Regardless of how Entrust is operated, there appears to be significant complexity in CA program that the browsers operate. On the flip side, Let’s Encrypt is basically effortless for me to use, as an end user of an LE secured site and as a developer. Why misallocate all this toil on root CA compliance on the one hand, when LE could redirect that labor towards something valuable instead? What is so challenging about giving LE full leadership on this issue? Where does the proverbial political strength of Entrust and similar entities come from, in an ecosystem where there are functionally 5 cooperating, more or less transparent entities that decide the trust of certificates for 99% of end users? Why does anyone care about any of the CAs?

Post reply on HN