A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…
WoSign and StartCom: Mozilla’s proposed conclusion
41–50 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#42Earlier quoted context omitted.
How many companies can survive a year without revenue? None I've ever worked at. Not only that, but their readmission after that year is uncertain! Mozilla gets to pick an auditor ( raises hand! pick me! ) that gets full access to their code. This is, I think, a higher bar than a new CA would have to clear. StartCom is a popular CA. Distrusting previously-issued certificates would be extremely disruptive. Moreover, i…
Not only is it a year without revenue... I imagine this will devastate their revenues in future years as existing customers up for renewal during that time will likely permanently migrate to another CA.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#43So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#44So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#45Earlier quoted context omitted.
Considering I believe one of the writers of this was from Google, I guess we can assume they'll likely follow? With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.
Does Chrome maintain its own trusted certificate list on any platform? IIRC, it uses the OS's trust store on Windows and macOS, and NSS (so, Mozilla's trust store) on Linux. So, it's up to Apple and Microsoft to handle this for Chrome users on those platforms.
CRLSets: https://dev.chromium.org/Home/chromium-security/crlsets
HSTS Preloading: https://hstspreload.appspot.com/
more: https://www.chromium.org/Home/chromium-security/security-faq...
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#46A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
By far the more important element here is not that the specific corporate entity gets nuked, but that it be demonstrated to all and sundry that the CA standards have teeth. That is what will keep the bad actors from "just" doing anything to get around the problem, not psychologically-appealing vengeance.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#47If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#48Earlier quoted context omitted.
Considering I believe one of the writers of this was from Google, I guess we can assume they'll likely follow? With both Chrome and Firefox no longer allowing certificates from them we can expect customers to no longer buy from them which will result in no more certificates even if Apple/Microsoft don't follow.
Does Chrome maintain its own trusted certificate list on any platform? IIRC, it uses the OS's trust store on Windows and macOS, and NSS (so, Mozilla's trust store) on Linux. So, it's up to Apple and Microsoft to handle this for Chrome users on those platforms.
https://www.chromium.org/Home/chromium-security/root-ca-poli...
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#49Earlier quoted context omitted.
Revoking them completely would be a pain for end users of StartCom and WoSign certificates, who had no way to know that their CA was incompetent and/or malicious. But this is a great way to choke out their business by the end of a year, since they can't sell any new products. Of course, it might be nice to actually revoke them so that in the future, "will my CA be revoked" is a realistic thing to think about when cho…
Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#50A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.