Earlier quoted context omitted.
They genuinely believe they are "too big to fail". They've got thousands of employees, they've been around for 30 years, they are a critical part of public infrastructure: surely something as trivial as a few weirdos in a mailing list couldn't instantly kill their entire business? Stuff like this happens when upper management has zero clue about the business they are in. They believe they are in the business of selli…
Perhaps they've decided to draw inspiration from https://bugzilla.mozilla.org/show_bug.cgi?id=647959 .
Entrust Certificate Distrust
91–100 of 118 posts
Re: Entrust Certificate Distrust
#92It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?
> How dysfunctional does a company have to be to let this happen? Surprised no one pointed to the nature of the business as a source of this behavior. In a non-innovative, compliance-based industry, you make money by cutting costs. This affects the entire business, as you find managers who are effective at cutting costs and architects/engineers who will work for lower salary. Multiply that over enough years, and we k…
>> I see three possible outcomes:
>> 1. The root programs continue to be lenient with Entrust indefinitely. Nothing changes.
>> 2. The root programs continue to be lenient with Entrust for a while, but eventually the mistakes pile up enough that one of the root programs pushes for distrust.
>> 3. The root programs immediately stop being lenient with Entrust. Entrust is forced to make internal changes to remain a CA.
It raises an interesting point about what constitutes a historical pattern of behavior, sufficient for infering future deficiencies reliably enough to take present action.
Here, the motivation seemed to be that (a) enough history had accumulated to estimate Entrust's rate of process improvement & (b) that rate was deemed insufficient. Which seems a decent metric: if perfection is not presently achieved, then remediation progress needs to be seen.
Re: Entrust Certificate Distrust
#93It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?
I saw company being killed by failed backup system. One unfortunate hardware failure, bad backups and company service goes offline with no way to recover in timely manner. Big clients require big compensation, company goes bankrupt. One shell script put in crontab could have prevented that, but nobody cared enough. It was not a big company, though. But consequences of one simple overlook were dire.
Which means their business continuity planning was bullshit.
The good news is this caused companies in the healthcare space (at least provider, facility, and insurer sides) to start asking more pointed BCP questions to their SaaS vendors.
Re: Entrust Certificate Distrust
#94Earlier quoted context omitted.
Exactly. I’d also like to be able to trust a certificate for a limited set of domains. This would be extremely valuable for all kinds of use cases.
IMO the problem is worse if considered from the perspective of the user. There is no visual distinction that the chain of trust goes back to a local admin managed store and that the admin can arbitrarily trust certificates outside their proprietary domain. It should be perfectly reasonable and probably required for an employee to be able to order reimbursed things like travel arraingements with a credit card on their…
In practice, complexity and customizability breeds ossification, because "safe" becomes the tiny sunset of common configuration.
I could definitely see network appliance vendors, IT network security admins, endpoint security vendors, etc. rapidly fucking up everything.
At least with delegation to browser vendors + certificate transparency logs, we have a semi standard path for a detrust like this to be forced without exploding the ecosystem.
Additionally, if there were more wiggle room, you'd alter the balance of power between browsers and CAs, which seems decently calibrated now.
Re: Entrust Certificate Distrust
#95Earlier quoted context omitted.
Entrust has BIMI certs which use a different root (CN = Entrust Verified Mark Root Certification Authority - VMCR1) and for which your choices of a BIMI certificate are: Entrust or Digicert. I doubt it makes as much money as their web certs (BIMI certs are not super common, and they are expensive to issue since there's an actual validation process that typically involves a public notary validating the ID of a corpora…
BIMI is a CA racket.
See arguments about red-warning unencrypted HTTP and how that pushed the web to update.
Add in that genAI is going to make plausible-looking phishing emails a lot easier for the world to generate en mass, and giving the everyperson something better than "decide if it looks suspicious" is important.
Re: Entrust Certificate Distrust
#96Earlier quoted context omitted.
All you need is one single [cc]?.gov as your client and you are in business forever.
How? If you want to sell public certs you need Google (and apple and Microsoft) to grant permission. Private certs are not that big a business.
Re: Entrust Certificate Distrust
#97Earlier quoted context omitted.
IMO the problem is worse if considered from the perspective of the user. There is no visual distinction that the chain of trust goes back to a local admin managed store and that the admin can arbitrarily trust certificates outside their proprietary domain. It should be perfectly reasonable and probably required for an employee to be able to order reimbursed things like travel arraingements with a credit card on their…
The local admin means "the user's employer's IT department", which, for the sake of a work laptop, they implicitly trust way more than Mozilla/Microsoft/Google/Apple etc who managed the public root stores.
Whether CA/B is good or bad at what it does, it puts about a thousand times more effort into the question of whether to install a CA certificate in the browser than a company that just bought the cheapest solution to one of its problems and wants to install the corresponding vendor certs.
For example: https://docs.umbrella.com/deployment-umbrella/docs/install-c...
How many things could be wrong with that system and cause user's traffic to be compromised web wide? What community is checking transparency logs and threatening Cisco to revoke their authority to sell that product? What would that even mean?
Re: Entrust Certificate Distrust
#98Earlier quoted context omitted.
How? If you want to sell public certs you need Google (and apple and Microsoft) to grant permission. Private certs are not that big a business.
after you sold a .gov then any discussion about not supporting your root means denying users access to that .gov service.
Re: Entrust Certificate Distrust
#99It always fascinates me when this happens. Don't the CAs understand that the browser vendors can and will kill their business if they don't comply with the rules? It's not like a fine that can be ignored. How dysfunctional does a company have to be to let this happen?
All you need is one single [cc]?.gov as your client and you are in business forever.
Re: Entrust Certificate Distrust
#100Earlier quoted context omitted.
after you sold a .gov then any discussion about not supporting your root means denying users access to that .gov service.
CA roots are not connected to tlds
Also roots can be TLD constrained, typically to ccTLD(s).