WoSign and StartCom: Mozilla’s proposed conclusion
71–80 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#72Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
https://groups.google.com/d/msg/mozilla.dev.security.policy/...
" 1) Are the first three shareholders listed in the attached file the same companies as the "Qihoo 360 Software (Beijing) Co., Ltd.", "Beijing Qifutong Technology Co., Ltd.", and "Beijing Yuan Tu Technology Co., Ltd." entities listed in Qihoo 360 SEC reports as VIEs or subsidiaries of VIEs? [Xiaosheng]: Yes, they are.
2) Does Qihoo 360, a Qihoo 360 subsidiary, a Qihoo 360 VIE, or a Qihoo 360 VIE subsidiary, or a combination of those own or control a majority of shares in WoSign? [Xiaosheng]: Yes, the combination of those own 84% of shares in Wosign."
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#73Earlier quoted context omitted.
Mozilla is killing StartCom. Chrome has not announced a decision yet, although I predict that they will also distrust.
It's pertinent in this matter that one of the authors of the report works on the Chromium TLS stack. But it's not clear to me whether Chrome has an independent CA program. They use the Microsoft CA store on Windows, and at some point were using NSS (and hence the Mozilla certs) on Unixes. I presume they can always just additionally block this CA in Chrome, though.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#74So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?
What exactly don't you like about Let's Encrypt? Besides Let's Encrypt, your other option is paying for a cert from GoDaddy or something. My two cents: don't give business to Comodo, given their horrible track record of sleaziness ( https://en.wikipedia.org/wiki/Comodo_Group#Controversies ).
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#75Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?
Why are you using S/MIME? You can still get free S/MIME certs from Comodo.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#76Re: WoSign and StartCom: Mozilla’s proposed conclusion
#77Earlier quoted context omitted.
It's pertinent in this matter that one of the authors of the report works on the Chromium TLS stack. But it's not clear to me whether Chrome has an independent CA program. They use the Microsoft CA store on Windows, and at some point were using NSS (and hence the Mozilla certs) on Unixes. I presume they can always just additionally block this CA in Chrome, though.
Pertinent, rather than poignant?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#78Earlier quoted context omitted.
It's pertinent in this matter that one of the authors of the report works on the Chromium TLS stack. But it's not clear to me whether Chrome has an independent CA program. They use the Microsoft CA store on Windows, and at some point were using NSS (and hence the Mozilla certs) on Unixes. I presume they can always just additionally block this CA in Chrome, though.
Ryan Sleevi authored the report in his capacity as a peer of the Mozilla CA Certificates Module, not as a Chrome/Google employee. See https://wiki.mozilla.org/CA:Policy_Participants Chrome does indeed use the platform CA store, but they can and do impose additional logic on top of it, such as requiring CT for Symantec, distrusting new CNNIC certs, or name-constraining ANSSI and India CCA.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#79Just curiosity: since this report is a Google Doc, how can one know that it has been really written by Mozilla? Shouldn't it be under the mozilla.org domain?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#80Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448
They're not "killing" anyone. They have reasonable doubt that the CA has misrepresented the truth and engaged in practices that violate the rules set forth by the CAB and those for inclusion in the Mozilla trust store. There will have to be consequences for else it means nothing. They're also very clear that they do not intend to invalidate any already issued certificates, only new ones after a specific, yet to be de…