Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

51–60 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#51

So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?

What exactly don't you like about Let's Encrypt? Besides Let's Encrypt, your other option is paying for a cert from GoDaddy or something. My two cents: don't give business to Comodo, given their horrible track record of sleaziness (https://en.wikipedia.org/wiki/Comodo_Group#Controversies).

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#52
post #42
post #41

Earlier quoted context omitted.

Not only is it a year without revenue... I imagine this will devastate their revenues in future years as existing customers up for renewal during that time will likely permanently migrate to another CA.

It looks like Mozilla and Google have created a set of circumstances where the rational next step would be to wind down WoSign/Startcom and just start a new company.

Which would require creating new roots to be submitted to Mozilla's CA program, and passing the bar for inclusion of a new CA.

That's a multi-year process, unless they can get another CA to cross-sign their root, like LE did. I doubt other CAs will be willing to carry that level of risk given the reputation of WoSign/StartCom.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#53
post #15

If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.

Even after this disclosures, a fully informed, rational agent would still choose WoSign if their price and service were the best. This is because WoSign's behavior does not specifically endanger their customers.

The SSL ecosystem relies on the trustworthiness of the certificate authorities. If one of them is compromised, the whole system is compromised, not just their customers. This cannot be solved by markets. Instead, it's heavily regulated.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#54
post #51

So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?

What exactly don't you like about Let's Encrypt? Besides Let's Encrypt, your other option is paying for a cert from GoDaddy or something. My two cents: don't give business to Comodo, given their horrible track record of sleaziness ( https://en.wikipedia.org/wiki/Comodo_Group#Controversies ).

I don't like the EFF, but I guess I will have to use Let's Encrypt if there's no other option.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#56

Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?

Why are you using S/MIME?

You can still get free S/MIME certs from Comodo.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#57
post #56

Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?

Why are you using S/MIME? You can still get free S/MIME certs from Comodo.

Mostly for fun.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#58
post #11

I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?

CA root lists are generally maintained on an OS level (Oracle does maintain a separate root list for Java). Linux doesn't really have a central CA, so in practice, the root certificate list for all of Linux usually comes from Mozilla.

Mozilla's CA policy is the only major policy where almost all discussion is public (indeed, its policy requires a public commentary period), so its decision is the most visible by far. Given that the major list vendors already collaborate in the CAB forum, it's likely that MS and Apple will follow the Mozilla/Google lead here. The prior Diginotar and Comodo scenarios involved all the vendors operating in tandem.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#60
post #50

A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.

Given WoSign's history of backdating SHA-1 certificates in violation of Mozilla's rules, I wouldn't be too surprised if they reuse that practice to get around the 1 year ban, at which point Mozilla will have to consider permanently distrusting them.

They've already considered it and are including this in their proposal:

> WoSign/StartCom could back-date certificates to get around this restriction. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.

Post reply on HN