Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

31–40 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#31

Earlier quoted context omitted.

Yes; malice is indefensible no matter the circumstances, mistakes may be defensible under certain circumstances or with certain responses by the mistakee.

as a brazilian i’m not sure if I’d prefer it to be malice or incompetence

As an American…why not both?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#32

This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.

[deleted]

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#33
post #30

Not clear (to me) in the original post -- was this done accidentally or intentionally?

As a CA, how does one accidentally issue a certificate for google.com? I mean, is there a scenario that isn't malicious?

Yes, if the interception system involved was meant only for resources within Brazil’s own agency networks.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#34
post #22

Earlier quoted context omitted.

Whomever has this fake certificate can run a server and say it's google.com and windows will say "yep you are" with the little green lock.

The certificate is for a specific IP address, no? And without DNS pointing google.com to that IP address, it's pretty useless.

Nope, certificates are issued for CNs(Common Name), also known as FQDNs (Fully qualified domain names). Something such as *.google.com, not IP addresses.

If they were issued for IP addresses they would have to reissue the certificate every time they spun up a new server. Also it's why if you spin up another server and make DNS point google.com to that server, it would not pass verification since the certificate you will be using on that server is not issued to *.google.com, but rather some other domain you own. The IP address plays no role in certificates.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#35

ICP-Brasil officially stopped emitting public-facing SSL/TLS certificates in October: https://www.gov.br/iti/pt-br/assuntos/noticias/indice-de-not... This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good.

[flagged]

Do you actually understand what's going here?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#36
post #10
post #7

Earlier quoted context omitted.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

I suppose it allows you to enable third party control and censorship. If you look at microsoft's censorship of bing in china for example, they are more than willing to bend the knee if it means they can get ahead.

As a brazillian, I find this very unlikely.

In 2013, when the same party was in power, SERPRO was tasked with replacing Microsoft in key aspects, such as government email (which was handled by Outlook Server at that time) and operating systems.

The main reason was fear of espionage. So, in reality, we are more afraid of the US spying on us than random internet dissidents.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#38

Earlier quoted context omitted.

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

what's the state's interest in having their CA built into windows?

Legitimate, or illegitimate?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#39

It gets worse. ICP-Brasil, the AC mentioned in the bug reports, the the government run agency responsible for all things related to digital signatures. Digitally signing a contract, a deed, accessing tax returns…

Unlike web browsers, digital signature use cases should perform revocation checks, so revoking the google.com certificate should solve that.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#40

Earlier quoted context omitted.

Yes; malice is indefensible no matter the circumstances, mistakes may be defensible under certain circumstances or with certain responses by the mistakee.

as a brazilian i’m not sure if I’d prefer it to be malice or incompetence

There is also the option of malicious incompetence, of course.
Post reply on HN