Live data from Hacker News

Chinese CA WoSign faces revocation after possibly issuing fake certificates

percya.com

81–90 of 116 posts

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#81
post #73
post #71

Earlier quoted context omitted.

Transferring certificates from an untrustworthy CA makes no sense. Burn the certificates. Websites should just obtain brand new ones from a different CA. If you are running a website that's important to you, this should be at most a one hour operation (or, if politics and procedures delay you in obtaining a new cert, maybe you should have planned ahead and kept two different certificates on hand already)

By transferring I meant re-issuing automatically a new certificate, not keeping the signature. Of course this requires to re-authenticate the request. And that process has to be automated. A bit like the renewal of the certificate should also be automated.

The validation requirements for 'Extended Validation' certificates can be onerous - complete with in-person ID checks, and photocopies of passports and driving licenses signed by public notaries. I'm not sure automated transfers would be possible.

I suppose you could downgrade on automatic transfer. I've heard people question the value of EV certs, and certainly a working DV cert is better than a revoked EV cert. Or you could insist every EV cert applicant verify their identity with two different CAs.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#82
post #15

I just went to delete these roots from my Windows system but it's not listed. It was in Firefox's list but not in Window's. Anyone know why?

The root certificates trusted by Windows are fetched from Microsoft's servers as needed. You can download all of them using the command:

    certutil -generateSSTFromWU roots.sst
Then if you open up roots.sst (it opens in certmgr.msc) and sort by Friendly Name, you should see the WoSign roots. You can then export these and import them into the Untrusted Certificates store if you wish to block WoSign as a trusted root.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#83
post #80

Earlier quoted context omitted.

on first google search: https://news.ycombinator.com/item?id=8982013 " It's 2015. They're using SHA-1 for everything (NOOOO!). They're based in China, which has just said it wants to ban encryption. It looks like they've messed up OSCP, so even their own cert doesn't pass. Oh, and RC4, TLS 1.0 "

Politicians in the US and UK have also claimed they want to ban encryption. Unless the CA is literally run by the government (which some Chinese CAs are, but not this one), it doesn't make sense to penalize them for dumb things their country's politicians say.

eh it's a longer quote taken out of context, not my words nor my opinion, but shows it's indeed not a respectable CA

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#84
post #76

Earlier quoted context omitted.

(e.g. there is no good reason for a CA in the US to be able to sign certificates with Chinese TLD CNs, and vice versa). Sure there is. If you have a .cn domain but don't trust Chinese companies not to MITM your site, you can get a cert from a foreign CA and then pin it using the HSTS preload list. That way, even if the registry hijacks the domain and sends people to a server with a valid (but fraudulent) cert, you're…

If you don't "trust Chinese companies not to MITM your site" then why do you trust CNNIC enough that you decided to register your domain in .cn?

Because by pinning the cert, I can reasonably make sure they can't abuse that power.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#85
post #80

Earlier quoted context omitted.

Politicians in the US and UK have also claimed they want to ban encryption. Unless the CA is literally run by the government (which some Chinese CAs are, but not this one), it doesn't make sense to penalize them for dumb things their country's politicians say.

eh it's a longer quote taken out of context, not my words nor my opinion, but shows it's indeed not a respectable CA

I wouldn't say it's out of context, I was clearly stating my worries when this CA was discussed here a couple of years ago.

I think something should be done, but it's not my call of course. Given we do have Let's Encrypt now, I wouldn't feel in the least bit sad in revoking the WoSign certs. Anyone affected can, and should, change.

It's disappointing to see my concerns back then were well-placed, and there are clear indications StartCom's and WoSign's backends are connected together somehow?! I don't know what's going on there exactly, and someone should definitely find out.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#86
post #78
post #39

Earlier quoted context omitted.

I think we should just pull the rug out. Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, mo…

> Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. Why? CAs just operate as a tax on sites. Having a certificate doesn't buy a site much; it's typically more for the _users'_ convenience, since they are the ones relying on the CA. Really, users should pay CAs (probably indirectly), and C…

For commercial sites, the users are paying indirectly - since the cost of CA would be surely rolled into the maintenance costs, which are surely part of the price of whatever the site is selling.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#87
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

> when their only crime is using a crap CA.

Their punishment would be having to pay for another certificate and install it and using a more reputable one and not necessarily the cheapest one around next time. I think in this case the punishment fits the crime perfectly.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#88
post #87
post #5

Traditionally it's difficult for browser vendors to revoke a root CA as they want to grandfather in old certificates, so existing sites don't have the rug pulled out from under their feet when their only crime is using a crap CA. Partial solutions include blocking the CA's certs based on the issuance date or insisting they hand over a list of the certs they've issued - but if the CA is going down in flames anyway, th…

> when their only crime is using a crap CA. Their punishment would be having to pay for another certificate and install it and using a more reputable one and not necessarily the cheapest one around next time. I think in this case the punishment fits the crime perfectly.

more reputable one and not necessarily the cheapest one

The two don't seem to be linked at all; Symantec's cheapest cert (non-EV, no-wildcard) costs $399 - almost 80x the cheapest ones - and yet they were caught issuing unauthorized certs.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#89
post #39

Earlier quoted context omitted.

I think we should just pull the rug out. Site operators need to be more aware of which CAs they're using, and need to feel some of the pain from the failure if they're going to shop for CAs based on anything except price. The behavior of consumers in the certificate marketplace is part of the systemic problem: nobody cares very much about their CA, as long as it causes the little padlock to display correctly (and, mo…

Site operators need to be more aware of which CAs they're using How? I've got no way to judge the security / responsibility of any CA. The amount of money that they charge may have no relation to their behaviour. I don't think anyone has claimed that the CAs who issued wrong certs were charging less than their competitors. You can't blame the CA customers for this.

You could say the same about your bank - even though you don't really know how they invest your deposit money, you try and gain an intuition based on other factors (stock price, professionalism, reputation, prestige, etc). Not saying these factors -> a good analysis of the creditworthiness of a financial institution but you get the idea.

Re: Chinese CA WoSign faces revocation after possibly issuing fake certificates

#90
post #79

Earlier quoted context omitted.

I won't comment on the specifics of this case, but a more nuanced approach regarding security is preferable because it favours transparency. If a vendor/CA/whatever knows that they will die if anything comes out, they will bury things like this even deeper.

> I won't comment on the specifics of this case, but a more nuanced approach regarding security is preferable because it favours transparency. Certificate Transparency solves a lot of this already. It'd be nice if you could flag your domain as being only acceptable from a CA of your choosing. I don't even think the false positives would be an issue as worst case you have security conscious customers not coming to you…

> It'd be nice if you could flag your domain as being only acceptable from a CA of your choosing.

HPKP pretty much solves this, and is already being used by a large number of high-value targets.

DNS Certification Authority Authorization (CAA) would also be fairly useful in this regard. It's essentially a DNS record set by a domain owner declaring which CAs are allowed to issue certificates for that domain. These records can then be checked by CAs prior to issuing certificates. It's more or less a defense-in-depth mechanism for other domain validation vulnerabilities, and would've probably prevented these incidents if implemented correctly, though not particularly useful if a CA is compromised completely. I suppose it could also be used by Certificate Transparency Monitors to automatically check if issued certificates are suspicious.

Unfortunately, it's not mandatory yet and so far I believe only a small number of CAs have adopted CAA (Let's Encrypt, DigiCert and possibly some others).

> Rather than signing everything with your top level cert, you sign a series of intermediate certs and use those to sign the end user keys.

This is what CAs already do, including WoSign. I'm not sure if signing end-entity certificates with the root key is even allowed by the Baseline Requirements. Unfortunately, having multiple intermediate certificates to limit the number of affected clients does not really help much if the question is whether a CA should be trusted at all due to their track record, which is what we're talking about here.

Post reply on HN