Live data from Hacker News

WoSign: Free two-year multi-domain SSL certificate

ohling.org

41–50 of 63 posts

Re: WoSign: Free two-year multi-domain SSL certificate

#41

Stolen right off of LowEndTalk.

The objective truth is that no theft has happened. Laws about theft are not applicable to copyright infringement.

But you're right, it's taken from LowEndTalk[1] and it remains unknown to us if the author asked for permission to copy the instructions to his or her blog.

[1]: http://www.lowendtalk.com/discussion/41289/free-chinese-2-ye...

Re: WoSign: Free two-year multi-domain SSL certificate

#42

They might've passed the WebTrust audit, but I'm still pretty worried about their security posture. Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice any CA in the world can issue certificates for any domain. Let's recap: It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes,…

You're completely right, and up voted because THIS IS AN SHA1 CERTIFICATE, IT WILL TRIGGER BROWSER WARNINGS, YOU DONT WANT IT should remain the top post, but David Cameron did actually win an election and is currently the Prime Minister of the UK.

Re: WoSign: Free two-year multi-domain SSL certificate

#43

They might've passed the WebTrust audit, but I'm still pretty worried about their security posture. Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice any CA in the world can issue certificates for any domain. Let's recap: It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes,…

They also offer SHA2; only their intermediate cert is SHA1.

Re: WoSign: Free two-year multi-domain SSL certificate

#44
post #42

They might've passed the WebTrust audit, but I'm still pretty worried about their security posture. Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice any CA in the world can issue certificates for any domain. Let's recap: It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes,…

You're completely right, and up voted because THIS IS AN SHA1 CERTIFICATE, IT WILL TRIGGER BROWSER WARNINGS, YOU DONT WANT IT should remain the top post, but David Cameron did actually win an election and is currently the Prime Minister of the UK.

[deleted]

Re: WoSign: Free two-year multi-domain SSL certificate

#45
post #43

They might've passed the WebTrust audit, but I'm still pretty worried about their security posture. Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice any CA in the world can issue certificates for any domain. Let's recap: It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes,…

They also offer SHA2; only their intermediate cert is SHA1.

…and they've signed their own certificates with SHA-1 because…?

Re: WoSign: Free two-year multi-domain SSL certificate

#46
post #43

Earlier quoted context omitted.

They also offer SHA2; only their intermediate cert is SHA1.

…and they've signed their own certificates with SHA-1 because…?

...because in China pre-SP3 Windows XP is still alive and doesn't work with SHA2

Re: WoSign: Free two-year multi-domain SSL certificate

#47
post #42

They might've passed the WebTrust audit, but I'm still pretty worried about their security posture. Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice any CA in the world can issue certificates for any domain. Let's recap: It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes,…

You're completely right, and up voted because THIS IS AN SHA1 CERTIFICATE, IT WILL TRIGGER BROWSER WARNINGS, YOU DONT WANT IT should remain the top post, but David Cameron did actually win an election and is currently the Prime Minister of the UK.

In the spirit of your most thorough pedantry, I thought I'd correct your correction to say that OP is right, David Cameron didn't win an election, he won a seat as an MP.

None of the parties achieved the 326 seats required for an overall majority under the First Past the Post system. The Conservatives won the largest number of votes and seats but under FPTP rules were 20 seats short.

Re: WoSign: Free two-year multi-domain SSL certificate

#48
post #43

They might've passed the WebTrust audit, but I'm still pretty worried about their security posture. Remember, unless you're pinning your certificate using DNSSEC+DANE or HPKP, in practice any CA in the world can issue certificates for any domain. Let's recap: It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. (So has Cameron in the UK, yes,…

They also offer SHA2; only their intermediate cert is SHA1.

So... they manage to get the lowest denominator of SHA1 and SHA2 (which will probably remain SHA1 forever, but still...) -- because it'd be enough to compromise only one of these?

Re: WoSign: Free two-year multi-domain SSL certificate

#49
post #47
post #42

Earlier quoted context omitted.

You're completely right, and up voted because THIS IS AN SHA1 CERTIFICATE, IT WILL TRIGGER BROWSER WARNINGS, YOU DONT WANT IT should remain the top post, but David Cameron did actually win an election and is currently the Prime Minister of the UK.

In the spirit of your most thorough pedantry, I thought I'd correct your correction to say that OP is right, David Cameron didn't win an election, he won a seat as an MP. None of the parties achieved the 326 seats required for an overall majority under the First Past the Post system. The Conservatives won the largest number of votes and seats but under FPTP rules were 20 seats short.

Good point. Such a pity the conservatives elect their own leader with preferential voting but campaigned against the public doing the same.

Re: WoSign: Free two-year multi-domain SSL certificate

#50
post #46

Earlier quoted context omitted.

…and they've signed their own certificates with SHA-1 because…?

...because in China pre-SP3 Windows XP is still alive and doesn't work with SHA2

Not the kind of security decision I want to see a CA make!

Which underlies the problems with PKIX: any CA can sign anything, just about. Lowest common denominator. I actually prefer DNSSEC there myself - yes, yes, I know, hear me out for a moment! - because even if it's hierarchical, it's single hierarchical from those who are supposed to control the DNS anyway. (Of course, that still introduces points of attack. It's reasonable for countries to control ccTLDs but I wouldn't mind seeing IANA control the others under international law. And it doesn't really do it very well.)

In practice both have big flaws, but at least one can be used to pin the other so the benefits of both can be realised. Distributed systems may win in the end, but we're only at the start of that journey.

Post reply on HN