Live data from Hacker News

StartSSL, please revoke me – My private key has been compromised

revokame.tonylampada.com.br

51–60 of 71 posts

Re: StartSSL, please revoke me – My private key has been compromised

#51

Why is the power of revocations in cert issuer's hands? As long as the private key is private, I don't see how a malicious entity could add your private key to the revocation list. In fact, a place in the revocation list should be reserved every time a cert is issued, possibly with a mechanism to trigger it with the private key. For example, if I send a message encrypted/signed with my private key to the revocation a…

> Why is the power of revocations in cert issuer's hands? As long as the private key is private Because a major reason for revocation is when the private key has been compromised.

>> Why is the power of revocations in cert issuer's hands? As long as the private key is private

>Because a major reason for revocation is when the private key has been compromised.

His point is that whoever compromised the key is not interested to put it in the revocation list. If he does it... well, he did the good thing.

Re: StartSSL, please revoke me – My private key has been compromised

#52
I never understood why people use StartSSL. Their service is horrible. The interface is far beyond ugly. You could get a SSL certificate in a nice and easy way for 4,99$ at http://www.ssls.com/. (They reselling from different CAs. They cheapest one is currently PositiveSSL)

Re: StartSSL, please revoke me – My private key has been compromised

#53

I never understood why people use StartSSL. Their service is horrible. The interface is far beyond ugly. You could get a SSL certificate in a nice and easy way for 4,99$ at http://www.ssls.com/ . (They reselling from different CAs. They cheapest one is currently PositiveSSL)

> I never understood why people use StartSSL

The difference between 4,99$ and 0$. I can bear a slow loading page that I can barely navigate through as long as I can save 4,99$ (or more).

Re: StartSSL, please revoke me – My private key has been compromised

#54

I never understood why people use StartSSL. Their service is horrible. The interface is far beyond ugly. You could get a SSL certificate in a nice and easy way for 4,99$ at http://www.ssls.com/ . (They reselling from different CAs. They cheapest one is currently PositiveSSL)

With StartSSL I've get multiple-domain wildcard (8 domains) cert for $59/year (or 2-3 years if you don't need to change it).

This is pretty hard to find in general, and the ssls.com interface does not make it any easier.

For example the same 8 domain wildcard Positive SSL Multi-Domain: £360

I could revoke my cert a dozen times a year and it would still be cheaper than anything else I've found - happy to be informed of viable competitors at a similar price though (not necessarily lower)

As someone with several side projects (like most of us - I assume) this type of certificate is essential if we are to use SSL at all.

Re: StartSSL, please revoke me – My private key has been compromised

#55

Earlier quoted context omitted.

Their stance is entirely correct Well it sounds like their stance is wrong if they've agreed to the Mozilla CA Certificate Maintenance Policy: CAs must revoke Certificates that they have issued upon the occurrence of any of the following events: ... the CA obtains reasonable evidence that the subscriber’s private key (corresponding to the public key in the certificate) has been compromised

It doesn't say it needs to be free . It's perfectly reasonable to charge a nominal handling fee, as other CAs do for their services. What's special is that StartSSL offers their basic certificates for free, but this shouldn't make people feel entitled. Especially when someone exposes their private key on purpose they don't deserve special treatment in my book.

Paying Class 2 customers, like myself, are also charged the fee.

Their basic free Class 1 certificates are advertised on their website as “No Charge, Unlimited + 100 % Free” and “No Kidding 100% FREE”.

It wasn’t hard for me to find the provision that revocations cost $24.90 in question 72 of the FAQ, but it’s not exactly highlighted either. It’s probably not something that most people think about; they probably assume that StartCom provides free certificates (and have the automated infrastructure to do so) for publicity and/or to up-sell paid services. And I did actually go to a paid StartSSL service, which I probably won’t renew.

This isn’t to say that I have a “right” to a free revocation, and I should read the fine print, but I think I’m justified in lowering my opinion of their business practices a few notches.

Re: StartSSL, please revoke me – My private key has been compromised

#56
post #31

Earlier quoted context omitted.

Have you realized that not only OpenSSL, but any exploitable bug in any software that runs on servers (PHP, Apache, nginx, Linux, etc) should theoretically invalidate any certificate that is stored on those servers?

Any exploitable bug that allows to access private keys should invalidate certificates. There are many security vulnerabilities that don't give access to private keys.

Even if there's no publically-known way of using a particular security vulnerability to get access to private keys, how are we to be sure that somebody (perhaps malicious) didn't find a way and are just keeping it a secret?

Re: StartSSL, please revoke me – My private key has been compromised

#57
post #7

I've used these guys in the past and quite like them, but yeah, this is poor PR and I hope they get pulled for not paying attention to, you know, the overall security of the trust product they're selling. I don't want lock-in on my SSL cert but it's effectively a contract if I have to pay a fee to break it and the SSL padlock on my domain is held hostage if I don't. Maybe someone should open a bug report on Bugzilla.…

There are arguments about this being "their right" to not give free cert revocation, since that's how their business model works. They give you free certificates, but then you must pay quite a bit to revoke them. That being said, PR wise, this was a pretty dumb move by them. It should've been a great PR opportunity for them, by submitting a blog post on HN about how serious this issue is and how they're going to allo…

I am a paid StartCom customer with a Class 2 certificate, and they’re charging us the fee too.

Re: StartSSL, please revoke me – My private key has been compromised

#58

Earlier quoted context omitted.

It doesn't say it needs to be free . It's perfectly reasonable to charge a nominal handling fee, as other CAs do for their services. What's special is that StartSSL offers their basic certificates for free, but this shouldn't make people feel entitled. Especially when someone exposes their private key on purpose they don't deserve special treatment in my book.

> CAs must revoke [...] I understand the word "must" to mean that they cannot add additional strings, such as payment, to their obligation to revoke the certificate. Is there another way of interpreting it that I am missing? I guess you could interpret it as "must provide a mechanism", but I can't see that that was the intent of the original document. Mozilla's use of the word "must" here I think is important, becaus…

I wouldn't have put it better myself. I just added a new update on the website.

Saturday, April 12, 09:50 (GMT-3)

OK, so here's my reply to Nikolai:

"Let me address this question.

> Anything about free revocations there?

It doesn't, but that's not relevant. It's pretty damn clear: You see the evidence, that alone should be enough for you to take action.

If you take Mozilla's policy by the letter, one doesn't even have to own a certificate to be able to request its revocation. All that should be needed is the evidence of compromise.

If I disclosed the private keys for a certificat I don't own, would you just ignore that information? Or would you come after the certificate owner demanding payment first?

You're a CA, A CA!!! You should be worried about the security of the internet above all things.

You should also be worried that you have a bunch of green padlocks around that don't mean what they once did. You're not worried about that. So in my opinion you don't deserve the trust of the internet anymore.

Cheers Tony"

Re: StartSSL, please revoke me – My private key has been compromised

#59

So now it's official. They got the evidence that the certificate is compromised yet they refuse to take action. If that's not violation of CA policy I don't know what is.

I think you're right, if there's evidence the key is compromised, they should revoke first. Then they should bill you, and if you choose not to pay, they should send it to a collections agency.

How about they revoke your free certificate for free, but if you want another certificate for the same domain, you have to pay for it.

Re: StartSSL, please revoke me – My private key has been compromised

#60

Why is the power of revocations in cert issuer's hands? As long as the private key is private, I don't see how a malicious entity could add your private key to the revocation list. In fact, a place in the revocation list should be reserved every time a cert is issued, possibly with a mechanism to trigger it with the private key. For example, if I send a message encrypted/signed with my private key to the revocation a…

What if someone hacked your server and stole, then deleted the private key? (Backing up private keys is bad practice.)

What if the CA notices they issued a fraudulent certificate?

Post reply on HN