Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

51–60 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#51
post #7

Earlier quoted context omitted.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

Windows CA program is governed by requirements like any other CA. Microsoft has ways to provision machines with enterprise CA roots so there is no advantage, and highly visible disadvantage, to adding a noncompliant CA to your trust store. I think that the theory that Microsoft will included it to sweeten a sale has no merit, unless you have evidence.

Most certificate trust stores have some certs in them that are sketchy, eg a bunch of university certs from all over Europe. These are slowly dropping off, presumably because it costs quite a bit to operate a CA in a compliant fashion and get it professionally audited.

Issuing a fake cert is grounds for removal from every certificate trust program I’m aware of, if it can’t be demonstrated that they found what went wrong and have fixed it so it can never happen again.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#52
post #39

It gets worse. ICP-Brasil, the AC mentioned in the bug reports, the the government run agency responsible for all things related to digital signatures. Digitally signing a contract, a deed, accessing tax returns…

Unlike web browsers, digital signature use cases should perform revocation checks, so revoking the google.com certificate should solve that.

The problem here isn't really that one mis-issued certificate, but rather the general problematic behavior of that CA reported in TFA.

If a CA can be convinced to issue a server certificate for google.com, would you feel very comfortable trusting their contract/deed/... signing certificates?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#53

Earlier quoted context omitted.

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

what's the state's interest in having their CA built into windows?

Getting your CA into a trust store means that every machine using that trust store will accept your certs. It’s not really necessary for a government or corporation to have a public CA in anyone’s trust store unless they want to issue certificates that everyone trusts. If they just need their own machines to trust their certificates, they can use the management utilities that come with Windows and with AD to distribute an “enterprise root”, which only their machines will trust. This is how most large companies and governments do it.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#54
post #33
post #30

Earlier quoted context omitted.

As a CA, how does one accidentally issue a certificate for google.com? I mean, is there a scenario that isn't malicious?

Yes, if the interception system involved was meant only for resources within Brazil’s own agency networks.

But that's not allowed for publicly trusted roots under any circumstances, right? Not sure if that would qualify as an accident.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#55
post #16

Earlier quoted context omitted.

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

Windows is less popular every year.

You need to show statistics to prove that, not just throw the statement out there, possibly only based on the vibes on HN.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#56
Microsoft seems to be casual about trusting CAs, isn't transparent in their inclusion decisions, and their trust store is quite large. Any reasonable website would only use a certificate trusted by a quorum of browsers (especially Chrome), so the benefit of the extraneous CAs seems low.

I'm not a Windows user, but I have to wonder if there's a way to use the Chrome trust store on Windows/Edge. I can't imagine trusting Microsoft's list.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#57
post #39

Earlier quoted context omitted.

Unlike web browsers, digital signature use cases should perform revocation checks, so revoking the google.com certificate should solve that.

I think the current "meta" is CAA records? https://blog.cloudflare.com/why-certificate-pinning-is-outda...

Correct, which Google is using:

https://www.nslookup.io/domains/google.com/dns-records/caa/

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#58
post #27

Earlier quoted context omitted.

what's the state's interest in having their CA built into windows?

States are themselves extraordinarily large IT enterprises, they generally want control of traffic and its transparency or protection, and they are large enough to get arrangements for that, though usually not this particular arrangement. Large enterprises in the US generally have the same capability, but not loaded into operating systems by default (that is: Walmart's ability to do this on its own network in no way…

If you're a large enterprise, then it's trivial to add yourself your own custom CA and save the cost/hassle of needing to deal with outside companies. The tradeoff being you need to manage it yourself vs basically paying this third party company to survive?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#59
post #7

Earlier quoted context omitted.

What is even the point of a web CA that isn't trusted by all of the major players? Is there one?

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

The solution seems straightforward: limit the trust in the CA to .BR domains.

[domain name typo fixed]

Post reply on HN