Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

71–80 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#71
post #43

Earlier quoted context omitted.

Also being issued on a major US holiday- when many are on PTO- does not help with the look.

During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.

Have you never worked at a multinational company?

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#72

This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.

Microsoft is all about bad looks

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#73
post #63
post #54

Earlier quoted context omitted.

But that's not allowed for publicly trusted roots under any circumstances, right? Not sure if that would qualify as an accident.

I think the parent is saying that if they meant to use the cert only internally (e.g., to monitor employees) then that would arguably not be malicious.

> (e.g., to monitor employees) then that would arguably not be malicious.

If only there was a way to monitor company equipment without issuing a cert for a public 3rd party.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#74
post #51

Earlier quoted context omitted.

These are generally government CAs, so, typically the situation is Microsoft sold the government Windows, and as part of that deal (at least tacitly) agreed to the CA being trusted, and so every system that's trusting these certificates is a Windows PC anyway, running Edge because the whole point was the government will only use Windows and pays Microsoft $$$. Why bake it into everybody else's Windows? If you make sa…

Windows CA program is governed by requirements like any other CA. Microsoft has ways to provision machines with enterprise CA roots so there is no advantage, and highly visible disadvantage, to adding a noncompliant CA to your trust store. I think that the theory that Microsoft will included it to sweeten a sale has no merit, unless you have evidence. Most certificate trust stores have some certs in them that are ske…

IMO, issuing a fake CA for one of the top (and highest risk) domains even once should be the end of that CA (and any other CAs managed by that org)

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#75

Earlier quoted context omitted.

Yes; malice is indefensible no matter the circumstances, mistakes may be defensible under certain circumstances or with certain responses by the mistakee.

as a brazilian i’m not sure if I’d prefer it to be malice or incompetence

Incompetence: operating a CA is difficult enough that sometimes people fuck up, but if the CA is corrupted, then that’s much worse.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#76

Microsoft seems to be casual about trusting CAs, isn't transparent in their inclusion decisions, and their trust store is quite large. Any reasonable website would only use a certificate trusted by a quorum of browsers (especially Chrome), so the benefit of the extraneous CAs seems low. I'm not a Windows user, but I have to wonder if there's a way to use the Chrome trust store on Windows/Edge. I can't imagine trustin…

They are not transparent because it is based on enabling sales.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#77
post #30

Not clear (to me) in the original post -- was this done accidentally or intentionally?

As a CA, how does one accidentally issue a certificate for google.com? I mean, is there a scenario that isn't malicious?

You know testing stuff like example.com ...

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#78
post #46
post #16

Earlier quoted context omitted.

Windows is less popular every year.

I feel confident in guessing that any net changes in Windows popularity have close to no relation to Microsoft's policies around trusted CA. The number of users who are worried about sketchy certificates being trusted by default are dwarfed by the number of users who don't have any idea what a "trusted CA" is but care about more "visible" things like UI changes, performance, and how hard Windows is pushing Edge and o…

It’s not becoming the users that are the decision makers. A few CTOs could make decisions based on this

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#79
post #43

Earlier quoted context omitted.

Also being issued on a major US holiday- when many are on PTO- does not help with the look.

During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.

For as big a country as Brazil? Totally. I've worked at companies that had minor code freezes for all sorts of holidays in countries we had a big client presence in, specifically to avoid releasing changes to client that wouldn't have engineers in-office to adapt to them.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#80

Can someone explain what could be done with that and by whom?

It's not entirely about this particular certificate (although this is bad, too). This is about a certificate authority giving someone who is NOT Google, a certificate that can be used to "prove" a server is Google. Accidental or not, this should not happen.

The "blast radius" is limited to Microsoft since they are the only ones that trust this particular certificate authority. Your non-Microsoft browser won't trust these certs. Your non-Microsoft OS, Java program, etc. etc. won't trust these certs.

Post reply on HN