Live data from Hacker News

StartSSL, please revoke me – My private key has been compromised

revokame.tonylampada.com.br

31–40 of 71 posts

Re: StartSSL, please revoke me – My private key has been compromised

#31
post #6

Earlier quoted context omitted.

How dare they give you a free service, and then decide to charge for a revocation which they had said they would charge for (and is meaningless because by default all browsers ignore revocations). Unfortunately for various historical fuckups, we consider self signed certificates to be more dangerous than cleartext unsecured http. Lots of scary warnings pop up. That is absurd. Starcom is helping fix this by issuing fr…

> The Mozilla CA policy does not include a provision for obvious trolling and posturing. This isn't really trolling, after Heartbleed we should consider all SSL certs used by OpenSSL based servers as compromised. This sites just tries to make the point more obvious by putting such compromised cert in public view.

Have you realized that not only OpenSSL, but any exploitable bug in any software that runs on servers (PHP, Apache, nginx, Linux, etc) should theoretically invalidate any certificate that is stored on those servers?

Re: StartSSL, please revoke me – My private key has been compromised

#34
post #9
post #7

I've used these guys in the past and quite like them, but yeah, this is poor PR and I hope they get pulled for not paying attention to, you know, the overall security of the trust product they're selling. I don't want lock-in on my SSL cert but it's effectively a contract if I have to pay a fee to break it and the SSL padlock on my domain is held hostage if I don't. Maybe someone should open a bug report on Bugzilla.…

So, to verify, would you rather pay a (smaller) fee upfront for every registration (effectively, insurance against revocation), rather than pay a (larger) fee if and only if you ever need to revoke? (Or, are you saying that StartSSL is somehow evil, because they refuse to do everything you ever wished they could do for you with no compensation of any kind?) (Is the issue simply that they won't revoke without a fee, e…

I think Startcom are morally in the right about the payment issue and to have whatever business model they want. But at the same time that's a separate issue from their responsibilities as a CA and if that's compatible with their business model. I got burned by Heartbleed and I was proactive about getting my certs revoked because it never occurred to me that I should beg for a free revoke because it wasn't my fault or something. But now I see that Startcom is in a tought position because they should be revoking the guy's cert and just billing him, but his backlash is not atypical and free cert offers probably select for the type of person who will avoid paying for things at all costs.

Re: StartSSL, please revoke me – My private key has been compromised

#36
Mozilla should just spin-off their own CA, pricing the service fairly as a non-profit. It's not like they aren't the gatekeepers anyway.

Users don't trust Verisign or StartSSL, they trust whoever Mozilla, Microsoft or Google trust. Stop accepting new CAs in to the browser whitelist, start a CA for the public good with a true open source, full disclosure mentality. Why not?

Re: StartSSL, please revoke me – My private key has been compromised

#38

Classic Big Lebowski moment: You're not wrong, you're just an asshole. Their stance is entirely correct. The customer used a file that StartCom provided in software that turns out to have had a security flaw. That's neither StartCom's problem nor liability. They didn't say "use this certificate with anything other than OpenSSL; you'll be sorry if you use OpenSSL," nor could they have foreseen it. On the other hand, s…

Their stance is entirely correct Well it sounds like their stance is wrong if they've agreed to the Mozilla CA Certificate Maintenance Policy: CAs must revoke Certificates that they have issued upon the occurrence of any of the following events: ... the CA obtains reasonable evidence that the subscriber’s private key (corresponding to the public key in the certificate) has been compromised

It doesn't say it needs to be free. It's perfectly reasonable to charge a nominal handling fee, as other CAs do for their services. What's special is that StartSSL offers their basic certificates for free, but this shouldn't make people feel entitled. Especially when someone exposes their private key on purpose they don't deserve special treatment in my book.

Re: StartSSL, please revoke me – My private key has been compromised

#39

Why is the power of revocations in cert issuer's hands? As long as the private key is private, I don't see how a malicious entity could add your private key to the revocation list. In fact, a place in the revocation list should be reserved every time a cert is issued, possibly with a mechanism to trigger it with the private key. For example, if I send a message encrypted/signed with my private key to the revocation a…

> Why is the power of revocations in cert issuer's hands? As long as the private key is private

Because a major reason for revocation is when the private key has been compromised.

Re: StartSSL, please revoke me – My private key has been compromised

#40
The author is running a business on the domains he's talking about (a crowdfunding site that takes a 3% fee [1]) so he should just regard it as an unplanned business expense and pay up if he feels it's so important for his certs to be revoked.

Not that revocation will have much practical effect on the unlikely event of his keys having been compromised, and an attacker considering his website important enough to MITM - and having the means to do so to a sufficiently large audience to make it worthwhile. Seems like a lot of fuss over nothing much, in this case.

EDIT: Also just to note that the private key he has shown on this website was compromised solely by him putting it there, and not extracted via Heartbleed. Indeed, the certificate was created a few days after the vulnerability was reported and fixed. Makes this strange cry for attention even more absurd.

[1] https://freedomsponsors.org/faq#How%20do%20payments%20work?

Post reply on HN