A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
81–90 of 233 posts
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#82This is a bad look. I expected the result would be Chrome and Firefox dropping trust for this CA, but they already don't trust this CA. Arguably, Microsoft/Windows trusting a CA that the other big players choose not to trust is an even worse look for Microsoft.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#83Earlier quoted context omitted.
During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.
Have you never worked at a multinational company?
There are whole startups designed to solve this, like PagerDuty.
I am now very curious to understand where your question comes from. There must be some misunderstanding here. You never went on-call or seen a friend do it?
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#84The simple solution would be to have independent entities offer trust assertions about CAs and to allow users to consider multiple entities' views in their decision about whether to trust. It's surprising this doesn't exist yet when the attack vector is so clear.
This is something more akin to a client software bug than a WebPKI issue. Any alternative PKI scheme you could come up with would still be subject to Microsoft cutting deals.
Admittedly DNSSEC has issues to put it mildly, but it does serve as a counterexample to your claim.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#85The system is deeply flawed, which is something I realized fifteen years ago when I was put into a situation where I had to use online banking. (Had to being the nearest branch of any bank was an hour long flight away, though there was an ice road you could use in the winter.) One of my first questions of the bank was: who issued their certificate. They didn't have a clue what I was talking about. I suppose I could have pushed the question until I found someone who did know, but I also realized that a random person asking about security would be flagged as suspicious. The whole process was based upon blind trust. Not just trust in the browser vendors to limit themselves to reputable CA, but of the CAs themselves and their procedures/policies, and who knows what else.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#86Tangentially related: The system is deeply flawed, which is something I realized fifteen years ago when I was put into a situation where I had to use online banking. (Had to being the nearest branch of any bank was an hour long flight away, though there was an ice road you could use in the winter.) One of my first questions of the bank was: who issued their certificate. They didn't have a clue what I was talking abou…
…what did the certificate say?
> whole process was based upon blind trust
If I offer someone a ride and they start quizzing me on what differential I’m driving, I’m going to ignore them. That isn’t requiring blind trust, it’s just the wrong place and way to get the information you’re asking for.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#87The simple solution would be to have independent entities offer trust assertions about CAs and to allow users to consider multiple entities' views in their decision about whether to trust. It's surprising this doesn't exist yet when the attack vector is so clear.
This is something more akin to a client software bug than a WebPKI issue. Any alternative PKI scheme you could come up with would still be subject to Microsoft cutting deals.
I think the parent is suggesting that users should be able to tune their trust stores. I'd imagine that trusting only the CAs that are in all the major trust stores (Google, Microsoft, Mozilla, and Apple) would be a reasonable policy. Few websites would choose a CA that falls outside that group.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#88Earlier quoted context omitted.
Have you never worked at a multinational company?
I did, multiple times with multiple countries. All of them had some sort of call rotation. Someone was always at the helm, _specially_ in infrastructure and security. There are whole startups designed to solve this, like PagerDuty. I am now very curious to understand where your question comes from. There must be some misunderstanding here. You never went on-call or seen a friend do it?
Red herring [1].
OP said it’s malicious or incompetent to release this on a U.S. holiday weekend. You asked if similar consideration would be given to Brazil. Multiple people chimed in that it would. You’re now pivoting to on-call capacity.
Any amount of on-call capacity can be saturated. That’s why competent multinationals avoid releasing while markets they’re likely to impact are sleeping or drunk. This is a high-level scheduling operation, however, so it’s reasonable for those lower in the organisation to be unaware why an update is being pushed next Tuesday instead of this.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#89Earlier quoted context omitted.
During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.
> Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? Yes. That's completely normal for companies that do business with Brazil.
In fact, your example is perfect. We're not talking about business. CAs are different.
In security and infrastructure, there's always someone working on holidays. The larger the organization, higher are the chances that some kind of rotation exists.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#90Earlier quoted context omitted.
I did, multiple times with multiple countries. All of them had some sort of call rotation. Someone was always at the helm, _specially_ in infrastructure and security. There are whole startups designed to solve this, like PagerDuty. I am now very curious to understand where your question comes from. There must be some misunderstanding here. You never went on-call or seen a friend do it?
> You never went on-call or seen a friend do it? Red herring [1]. OP said it’s malicious or incompetent to release this on a U.S. holiday weekend. You asked if similar consideration would be given to Brazil. Multiple people chimed in that it would. You’re now pivoting to on-call capacity. Any amount of on-call capacity can be saturated. That’s why competent multinationals avoid releasing while markets they’re likely…
Rotations exist, specially in large organizations, or when there's shared responsibility.
Now we're talking nonsense about "you said, he said", this conversation makes no sense. I am much less invested in this than you think.