Live data from Hacker News

Windows Certificate Manager does not display the complete trust list

hexatomium.github.io

91–100 of 103 posts

Re: Windows Certificate Manager does not display the complete trust list

#91
post #37

Earlier quoted context omitted.

Please don't call commenters "apologists" on HN.

While I agree that UnoriginalGuy's post could have been phrased in a more neutral manner, the post he was replying to referred to the article as "linkbait" based on a "Windows bashing meme." Is that a neutral phrasing? Given that the article was revealing new information to most of the people here, I strongly disagree that the article is "linkbait." I think you are personalizing the debate in exactly the way you are…

There really aren't many respectful ways to call someone an apologist or saying someone writes linkbaits. There is the Windows bashing meme (I, personally, don't like Windows very much) but this article has shown an interesting fact about Windows management UIs that, probably, Microsoft should rework a bit. And then there are the triggers brudgers and tptacek mentioned. We are human and fallible and we should keep that in mind as much as humanly possible.

Re: Windows Certificate Manager does not display the complete trust list

#92
post #3

Earlier quoted context omitted.

1) Because MSFT provides great corporate support for desktops. Keyword: great. Not good. Great. 2) Because people are used to it. 3) Because Office products are the de facto standard, and they run best on windows. I could go on, but you get the point.

Everyone talks about how great the alternatives for office are. Buy they are good. Not great. Even office word online is better than Google docs.

It really depends on what you are doing. If it's formatting documents for printing, you're right. If, however, you want a document all 30 participants in a group can collaboratively edit, Google is the way to go. I've used it for ad-hoc voting on group issues (every voter would add a character to the list item they favored) and it held well up to 50 people.

Re: Windows Certificate Manager does not display the complete trust list

#93
post #90

What seems to be happening with Windows is that Microsoft is making the machine more a slave of their services with each new release. It's as if they're trying to catch up with Chromebooks, which are totally slaved to Google. Especially since Windows 10 is free with ads. Treating the local certificate store as a cache to the main certificate store at Microsoft HQ is consistent with this. How difficult it is to hijack…

They are transmitted over an unencrypted channel, but the CTL files themselves (authroot.stl and disallowedcert.stl) are signed by Microsoft so it's fine. Any modification in transit can be detected and presumably will cause them not to be updated.

Re: Windows Certificate Manager does not display the complete trust list

#94
post #90

What seems to be happening with Windows is that Microsoft is making the machine more a slave of their services with each new release. It's as if they're trying to catch up with Chromebooks, which are totally slaved to Google. Especially since Windows 10 is free with ads. Treating the local certificate store as a cache to the main certificate store at Microsoft HQ is consistent with this. How difficult it is to hijack…

They are transmitted over an unencrypted channel, but the CTL files themselves (authroot.stl and disallowedcert.stl) are signed by Microsoft so it's fine. Any modification in transit can be detected and presumably will cause them not to be updated.

So an attacker could return an old "disallowedcert.stl" to re-activate a revoked cert?

Re: Windows Certificate Manager does not display the complete trust list

#95
post #94

Earlier quoted context omitted.

They are transmitted over an unencrypted channel, but the CTL files themselves (authroot.stl and disallowedcert.stl) are signed by Microsoft so it's fine. Any modification in transit can be detected and presumably will cause them not to be updated.

So an attacker could return an old "disallowedcert.stl" to re-activate a revoked cert?

It would be interesting to try. There's a sequence number in the CTL which could prevent this type of attack, but I don't know if it's actually checked against that which is currently stored.

Re: Windows Certificate Manager does not display the complete trust list

#96

Earlier quoted context omitted.

The past several printers I've had... I just had to open the add printer dialog (which is more of a pain than it should be) and it would just detect the printer.. this is from win7 through 10. Now getting a new printer (new hardware) installed in Linux isn't usually so easy.. unless you're using a fairly mainstream HP Laser printer, which is actually what I recommend because it's so straight forward. Outside of that…

With linux I usually just plug it in then hit print in the application. Then it prints... I've never run into a consumer model that needed installing in any way. I may just have been lucky.

I tend to use network printers...

Re: Windows Certificate Manager does not display the complete trust list

#97

Earlier quoted context omitted.

The past several printers I've had... I just had to open the add printer dialog (which is more of a pain than it should be) and it would just detect the printer.. this is from win7 through 10. Now getting a new printer (new hardware) installed in Linux isn't usually so easy.. unless you're using a fairly mainstream HP Laser printer, which is actually what I recommend because it's so straight forward. Outside of that…

I've an epson wifi printer and every time it gets a different ip windows can't find it anymore. I used to have it on a dns reserved ip but damned new telco router doesn't have that option since I upgrades to fiber. Every time the epson setup wants to restart the whole computer to start the detection and it is so annoying, I just let any other airprint device do the thing.

Does the epson itself have a web-ui that you can set a hard-coded address to?

I usually just set all mine in the router, but as you said, that doesn't work for you.

Re: Windows Certificate Manager does not display the complete trust list

#98
post #34

Earlier quoted context omitted.

People that understand what certmgr.msc does (or should do) would immediately realize that it's not telling the full story.

I'm not a web developer, I am not intimately familiar with the intricate details of SSL, and yet I understand what a root store is and how it works. I have used certmgr.msc in the past, understanding that it should show me the certificates trusted by the system -- no more, no less. I did not immediately realize that it was not showing me all the certs my system trusts and I would like to know how I could have immedia…

its more than reasonable. you would have to not only know what certmgr is and what it does, but also what it SHOULD be doing in order to know it wasent doing it.

that would require specific knowledge about the CA ecosystem and who is trusted. hardly anyone knows that.

Re: Windows Certificate Manager does not display the complete trust list

#99

Windows isn't lying. Microsoft openly lists what certificates Windows includes on their site. The fact the root certificate store on your machine only lists certificates it actually contains is to be expected. This is just a UI failure.

When an American company lies, it's only a UI failure.

Why, specifically, American companies? I've encountered countless companies from other countries that lie.

Re: Windows Certificate Manager does not display the complete trust list

#100
post #84

Earlier quoted context omitted.

While I agree that UnoriginalGuy's post could have been phrased in a more neutral manner, the post he was replying to referred to the article as "linkbait" based on a "Windows bashing meme." Is that a neutral phrasing? Given that the article was revealing new information to most of the people here, I strongly disagree that the article is "linkbait." I think you are personalizing the debate in exactly the way you are…

Totally fair point. I'm not invested in the debate so much as the word "apologist" sets me off.

How could that word possibly set you off? It's a common word in the English language, and couldn't possibly be offensive by any stretch of the word.

> a person who offers an argument in defense of something controversial.

Is it just me, or are the majority of online communities that I visit becoming overrun with people that get offended by the slightest amount of bold or confrontational behavior?

Post reply on HN