Live data from Hacker News

Remediation Plan for WoSign and StartCom

groups.google.com

51–54 of 54 posts

Re: Remediation Plan for WoSign and StartCom

#51
post #48

Earlier quoted context omitted.

A 1 year ban is a long time for a company that sells certs. It might be the end of Wosign.

Interestingly - this is a ban on their roots. How much do you want to bet they're already working out how to supply new and renewing customers with certs provided by some other CA? I notice the most recent StartSSL cert I got has a 3 year validity instead of their previous standard of 1 year - presumably in the hope that when my cert needs renewing they'll be able to provide that service. (I do have a handful of thei…

How about AWS Certificate Manager? Their certificates are free and integrated with AWS services like ELB.

https://aws.amazon.com/certificate-manager/

(No doubt they're free because they're integrated with AWS services and can't be used elsewhere.)

Re: Remediation Plan for WoSign and StartCom

#52
post #2

So they are actually kicking out StartCom as well. Is this new? Apple was quick to move to kick out WoSign but they seemed to keep StartCom around. https://support.apple.com/en-us/HT204132

WoSign brought StartCom but didn't tell anyone (against Mozilla's root cert policy) and insisted they were separate businesses when called out on it. Mozilla looked into it, found evidence that StartCom was now owned by WoSign and WoSign finally came clean they owned StartCom.

The reasons StartCom is being distrusted too is because the WoSign code base (that a couple of parts are shared with StartCom including the issuance tech) has been found to be buggy so until qihoo 360 (WoSigns parent company) can prove that WoSign and StartCom are now 2 complete separate businesses as part of qihoo 360's plan to remove WoSigns CEO and separate the companies the loss of trust has to be applied to both.

Oh and that loss of trust... WoSign's CEO (someone who has been in on CA/B forum meetings discussing the sun setting of SHA1 certs) authorised a backdated SHA1 cert to be issued for an AU payment processor and bypassing the legit method of applying for one (which he was also at the meetings that set up the SHA1 exception process) using StartCom's root while insisting the two were CA's were not linked.

So Mozilla have said if qihoo 360 break up WoSign and StartCom (as qihoo 360 proposed), StartCom doesn't share WoSign's infrastructure after the break up and can prove this to the Mozilla community that StartCom and regain the trust of the Mozilla community they won't have to wait the min year to reapply.

Apple were quick to kick WoSign but qihoo 360/StartCom had requested a meeting with Mozilla to discuss a mitigation plan (Relieve WoSign's CEO oh his duties, separate the two CA's, put in respected security people as CEO's in the two broken up CA's) to get back on the road to solving this fucking mess.

Guess that looking at the evidence Mozilla released Apple's root team decided that WoSign had already lost their trust but wanted to hear out qihoo 360/StartCom before making a decision on StartCom too.

Re: Remediation Plan for WoSign and StartCom

#53
post #45

Earlier quoted context omitted.

They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.

Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops. By the way, anyone knows a cheaper wildcard certificate provider?

I've used Gandi just about my entire life for DNS & Certs. It was probably their tagline that sold me.

Anyhoo, they do wildcard for starting at 120,00 € excl. VAT/year.

https://www.gandi.net/

Re: Remediation Plan for WoSign and StartCom

#54
post #45

Earlier quoted context omitted.

They wouldn't let you renew them either unless you revoked first... Revocation cost $59 at the time. Was painful.

Certificates are very expensive with most providers, $59 is a bargain depending on your needs. The sole reason I've been staying with StartSSL is I've SSL'd all my subdomains (it's awesome for Postgres, for example), and a wildcard certificate costs $300 to $500 at all other shops. By the way, anyone knows a cheaper wildcard certificate provider?

I had over 100+ domains with StartSSL's free service. They worked for my needs. Revocation cost a lot of money for something that was not my fault.
Post reply on HN