Live data from Hacker News

Entrust Certificate Distrust

security.googleblog.com

61–70 of 118 posts

Re: Entrust Certificate Distrust

#61
post #3

The issues identified really show a dumpster fire: https://bugzilla.mozilla.org/buglist.cgi?o2=greaterthaneq&sh... Directly from Entrust: "Yes, there has been ongoing internal discussion and reflection on the issues found in this and other incidents, which has led to the action items described previously and ongoing changes, including the decision to revoke the certificates affected by this bug. Exceptional circumsta…

A honest translation from the corporate speak would be

We’ve been endlessly talking about our repeated screw-ups, which led us to revoke the affected certificates. If subscribers want an exception, they need to come up with an extraordinary excuse. We don't care, so we demand clear and strict rules about what counts as “exceptional circumstances” that apply to all CAs, and these should be updated in the CA/B Forum requirements. We are big, who are you?

... it's not promising

Re: Entrust Certificate Distrust

#63
post #37
post #27

Earlier quoted context omitted.

They genuinely believe they are "too big to fail". They've got thousands of employees, they've been around for 30 years, they are a critical part of public infrastructure: surely something as trivial as a few weirdos in a mailing list couldn't instantly kill their entire business? Stuff like this happens when upper management has zero clue about the business they are in. They believe they are in the business of selli…

Perhaps they've decided to draw inspiration from https://bugzilla.mozilla.org/show_bug.cgi?id=647959 .

Thanks for this link, reading through it (and the bugs referenced in it) was a delight this afternoon.

Re: Entrust Certificate Distrust

#64

All the google root security team's due diligence email are just a list of links to firefox's bugzilla who documented and followed up on all the issues. https://groups.google.com/a/ccadb.org/g/public/c/29CRLOPM6OM...

Mozilla's bugzilla is the de-facto site for coordinating issues in CA/B.

Any root program will refer to it for context on issues.

Re: Entrust Certificate Distrust

#66
post #5

I wonder if Entrust can survive this. Even if Web-PKI doesn't account for the majority of their income (which it might, I genuinely don't know) this is a huge blow to their credibility. And for a CA, credibility is everything

> I wonder if Entrust can survive this

They've pivoted to payment cards.

Re: Entrust Certificate Distrust

#68
post #28

Earlier quoted context omitted.

api.cybersource.com This is gonna cause me some headaches, along with everyone else who processes payments through Cybersource, and possibly others :(

CYBS Engineer here. We're already working on it. Keep an eye for merchant notifications if you use certificate pinning. Now, back to rotating certificates....

Maybe you (or anyone) could shed light on something for me?

I'm sure leaf certificate pinning is very common among your customers. Assuming that pinning is a manual process where customers decide to implicitly trust a specific cert, what's the point of using a third party CA for those customers all?

Does anybody self-sign or use a private CA on specific endpoints with longer certificate validity, and let the pinning customers use those?

Re: Entrust Certificate Distrust

#69
post #23

Earlier quoted context omitted.

Entrust makes a ton of revenue from hardware-related products (for example, printing ID cards), so it is far from the end.

Right up until the next contract renewal. "Not trustworthy enough to secure a basic website" isn't exactly a great look.

Untrusted by Google is what most laypeople will get out of it.

Re: Entrust Certificate Distrust

#70
post #53

> Additionally, should a Chrome user or enterprise explicitly trust any of the above certificates on a platform and version of Chrome relying on the Chrome Root Store (e.g., explicit trust is conveyed through a Group Policy Object on Windows), the SCT-based constraints described above will be overridden and certificates will function as they do today. This continues to annoy me. Chrome (and other browsers) have detai…

I don't understand what is annoying about this. Wouldn't it be more annoying for Chrome not to offer end users a way to override policy decisions they make in a Google office halfway across the world about what websites you can view on your own laptop?
Post reply on HN