Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

41–50 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#41
post #18

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…

Not only is it a year without revenue... I imagine this will devastate their revenues in future years as existing customers up for renewal during that time will likely permanently migrate to another CA.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#42
post #41
post #18

Earlier quoted context omitted.

How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…

Not only is it a year without revenue... I imagine this will devastate their revenues in future years as existing customers up for renewal during that time will likely permanently migrate to another CA.

It looks like Mozilla and Google have created a set of circumstances where the rational next step would be to wind down WoSign/Startcom and just start a new company.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#45

Earlier quoted context omitted.

Considering I believe one of the writers of this was from Google, I guess we can assume they'll likely follow? With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.

Does Chrome maintain its own trusted certificate list on any platform? IIRC, it uses the OS's trust store on Windows and macOS, and NSS (so, Mozilla's trust store) on Linux. So, it's up to Apple and Microsoft to handle this for Chrome users on those platforms.

Yes, Chrome generally uses the OS trust store as "trust roots", however Chrome layers on additional validation and pinning in the Chrome code:

CRLSets: https://dev.chromium.org/Home/chromium-security/crlsets

HSTS Preloading: https://hstspreload.appspot.com/

more: https://www.chromium.org/Home/chromium-security/security-faq...

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#46

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

To the other observations, I'd also observe that in a world of corporate entities, there isn't a meaningful way to permanently eliminate a CA. Bad actors can always dissolve the old entity, form a new one with the same policies and any of the same people you'd like, and do the same thing. Banning the existing corporation for a year is about all you can do; the more time that goes by the fuzzier it becomes as to what exactly that "entity" is.

By far the more important element here is not that the specific corporate entity gets nuked, but that it be demonstrated to all and sundry that the CA standards have teeth. That is what will keep the bad actors from "just" doing anything to get around the problem, not psychologically-appealing vengeance.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#47
post #15

If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.

The browsers will distrust the CA. Which will, in all likelyhood, lead to their bankruptcy.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#48

Earlier quoted context omitted.

Considering I believe one of the writers of this was from Google, I guess we can assume they'll likely follow? With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.

Does Chrome maintain its own trusted certificate list on any platform? IIRC, it uses the OS's trust store on Windows and macOS, and NSS (so, Mozilla's trust store) on Linux. So, it's up to Apple and Microsoft to handle this for Chrome users on those platforms.

Chrome uses OS CA store. But, it has 'Removal of Trust' cluase which expects CA store to follow some guidelines. Starcom might be in covered in that guideline. So, blacklisting a CA store is possible.

https://www.chromium.org/Home/chromium-security/root-ca-poli...

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#49
post #19
post #8

Earlier quoted context omitted.

Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…

Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.

The fact that they're honoring previous certificates is a good thing. It's a demonstration from Mozilla and Google that CAs with large customer bases have very little leverage in disputes like this: Mozilla will respond with the corrective measure that causes maximum pain for the CA business and minimal pain for the CA's previous customers.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#50

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

Given WoSign's history of backdating SHA-1 certificates in violation of Mozilla's rules, I wouldn't be too surprised if they reuse that practice to get around the 1 year ban, at which point Mozilla will have to consider permanently distrusting them.
Post reply on HN