Earlier quoted context omitted.
[flagged]
Do you actually understand what's going here?
A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
91–100 of 233 posts
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#92Earlier quoted context omitted.
> You never went on-call or seen a friend do it? Red herring [1]. OP said it’s malicious or incompetent to release this on a U.S. holiday weekend. You asked if similar consideration would be given to Brazil. Multiple people chimed in that it would. You’re now pivoting to on-call capacity. Any amount of on-call capacity can be saturated. That’s why competent multinationals avoid releasing while markets they’re likely…
You can totally ignore the red herring and focus on the first part. In the end I was just paraphrasing the comment I replied to. Rotations exist, specially in large organizations, or when there's shared responsibility. Now we're talking nonsense about "you said, he said", this conversation makes no sense. I am much less invested in this than you think.
Straw man [1]. Nobody claimed otherwise.
Rotation or always-on isn’t a substitute for being aware of your customers. Good culture permeate this throughout the organisation. Competent ones have someone at the top ensuring controls are followed.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#93Earlier quoted context omitted.
Also being issued on a major US holiday- when many are on PTO- does not help with the look.
During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.
You’re not. Someone above you should be. Otherwise that’s incompetence.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#94Earlier quoted context omitted.
But that's not allowed for publicly trusted roots under any circumstances, right? Not sure if that would qualify as an accident.
I think the parent is saying that if they meant to use the cert only internally (e.g., to monitor employees) then that would arguably not be malicious.
I don't know that's what happened here, though; there are malicious possible explanations!
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#95Earlier quoted context omitted.
I suppose it allows you to enable third party control and censorship. If you look at microsoft's censorship of bing in china for example, they are more than willing to bend the knee if it means they can get ahead.
As a brazillian, I find this very unlikely. In 2013, when the same party was in power, SERPRO was tasked with replacing Microsoft in key aspects, such as government email (which was handled by Outlook Server at that time) and operating systems. The main reason was fear of espionage. So, in reality, we are more afraid of the US spying on us than random internet dissidents.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#96Earlier quoted context omitted.
States are themselves extraordinarily large IT enterprises, they generally want control of traffic and its transparency or protection, and they are large enough to get arrangements for that, though usually not this particular arrangement. Large enterprises in the US generally have the same capability, but not loaded into operating systems by default (that is: Walmart's ability to do this on its own network in no way…
If you're a large enterprise, then it's trivial to add yourself your own custom CA and save the cost/hassle of needing to deal with outside companies. The tradeoff being you need to manage it yourself vs basically paying this third party company to survive?
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#97Earlier quoted context omitted.
This is something more akin to a client software bug than a WebPKI issue. Any alternative PKI scheme you could come up with would still be subject to Microsoft cutting deals.
Can you explain? I think the parent is suggesting that users should be able to tune their trust stores. I'd imagine that trusting only the CAs that are in all the major trust stores (Google, Microsoft, Mozilla, and Apple) would be a reasonable policy. Few websites would choose a CA that falls outside that group.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#98Earlier quoted context omitted.
But that's not allowed for publicly trusted roots under any circumstances, right? Not sure if that would qualify as an accident.
I think the parent is saying that if they meant to use the cert only internally (e.g., to monitor employees) then that would arguably not be malicious.
Or to redirect to an internal, no doubt pitched as more secure, search engine.
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#99Earlier quoted context omitted.
I feel confident in guessing that any net changes in Windows popularity have close to no relation to Microsoft's policies around trusted CA. The number of users who are worried about sketchy certificates being trusted by default are dwarfed by the number of users who don't have any idea what a "trusted CA" is but care about more "visible" things like UI changes, performance, and how hard Windows is pushing Edge and o…
It’s not becoming the users that are the decision makers. A few CTOs could make decisions based on this
Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
#100Earlier quoted context omitted.
Can you explain? I think the parent is suggesting that users should be able to tune their trust stores. I'd imagine that trusting only the CAs that are in all the major trust stores (Google, Microsoft, Mozilla, and Apple) would be a reasonable policy. Few websites would choose a CA that falls outside that group.
Users can tune their own trust stores.