Live data from Hacker News

A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

follow.agwa.name

91–100 of 233 posts

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#92
post #90

Earlier quoted context omitted.

> You never went on-call or seen a friend do it? Red herring [1]. OP said it’s malicious or incompetent to release this on a U.S. holiday weekend. You asked if similar consideration would be given to Brazil. Multiple people chimed in that it would. You’re now pivoting to on-call capacity. Any amount of on-call capacity can be saturated. That’s why competent multinationals avoid releasing while markets they’re likely…

You can totally ignore the red herring and focus on the first part. In the end I was just paraphrasing the comment I replied to. Rotations exist, specially in large organizations, or when there's shared responsibility. Now we're talking nonsense about "you said, he said", this conversation makes no sense. I am much less invested in this than you think.

> Rotations exist

Straw man [1]. Nobody claimed otherwise.

Rotation or always-on isn’t a substitute for being aware of your customers. Good culture permeate this throughout the organisation. Competent ones have someone at the top ensuring controls are followed.

[1] https://en.m.wikipedia.org/wiki/Straw_man

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#93
post #43

Earlier quoted context omitted.

Also being issued on a major US holiday- when many are on PTO- does not help with the look.

During carnival we brazillians often take 3 or 4 days leave. Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave? On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays. In fact, we're not even aware of most US holidays. It is likely to be a coincidence.

> we're not even aware of most US holidays

You’re not. Someone above you should be. Otherwise that’s incompetence.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#94
post #63
post #54

Earlier quoted context omitted.

But that's not allowed for publicly trusted roots under any circumstances, right? Not sure if that would qualify as an accident.

I think the parent is saying that if they meant to use the cert only internally (e.g., to monitor employees) then that would arguably not be malicious.

It would not be malicious. I don't think there's a serious argument here (bearing in mind that in the airless vacuum of a message we can, of course, argue anything).

I don't know that's what happened here, though; there are malicious possible explanations!

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#95
post #36
post #10

Earlier quoted context omitted.

I suppose it allows you to enable third party control and censorship. If you look at microsoft's censorship of bing in china for example, they are more than willing to bend the knee if it means they can get ahead.

As a brazillian, I find this very unlikely. In 2013, when the same party was in power, SERPRO was tasked with replacing Microsoft in key aspects, such as government email (which was handled by Outlook Server at that time) and operating systems. The main reason was fear of espionage. So, in reality, we are more afraid of the US spying on us than random internet dissidents.

As a non Brazilian, sometimes when a government says a company is spying on its citizens, they mean that they want access, too, to the spying and censoring apparatus.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#96
post #58
post #27

Earlier quoted context omitted.

States are themselves extraordinarily large IT enterprises, they generally want control of traffic and its transparency or protection, and they are large enough to get arrangements for that, though usually not this particular arrangement. Large enterprises in the US generally have the same capability, but not loaded into operating systems by default (that is: Walmart's ability to do this on its own network in no way…

If you're a large enterprise, then it's trivial to add yourself your own custom CA and save the cost/hassle of needing to deal with outside companies. The tradeoff being you need to manage it yourself vs basically paying this third party company to survive?

That's true, but in the bad-old-days of the antidiluvian WebPKI it was somewhat routine to sell big companies CA=YES certs simply to allow them to do this universally without pushing out updates to all their endpoints. It was a terrible, bad practice, and so far as I know it's completely dead now --- except for Microsoft, I guess.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#97
post #19

Earlier quoted context omitted.

This is something more akin to a client software bug than a WebPKI issue. Any alternative PKI scheme you could come up with would still be subject to Microsoft cutting deals.

Can you explain? I think the parent is suggesting that users should be able to tune their trust stores. I'd imagine that trusting only the CAs that are in all the major trust stores (Google, Microsoft, Mozilla, and Apple) would be a reasonable policy. Few websites would choose a CA that falls outside that group.

Users can tune their own trust stores.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#98
post #63
post #54

Earlier quoted context omitted.

But that's not allowed for publicly trusted roots under any circumstances, right? Not sure if that would qualify as an accident.

I think the parent is saying that if they meant to use the cert only internally (e.g., to monitor employees) then that would arguably not be malicious.

> if they meant to use the cert only internally (e.g., to monitor employees)

Or to redirect to an internal, no doubt pitched as more secure, search engine.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#99
post #46

Earlier quoted context omitted.

I feel confident in guessing that any net changes in Windows popularity have close to no relation to Microsoft's policies around trusted CA. The number of users who are worried about sketchy certificates being trusted by default are dwarfed by the number of users who don't have any idea what a "trusted CA" is but care about more "visible" things like UI changes, performance, and how hard Windows is pushing Edge and o…

It’s not becoming the users that are the decision makers. A few CTOs could make decisions based on this

If the rationale in the parent comment for this behavior is correct, it sounds like a lot of people making the decision to use Windows are doing it _because_ of behavior like this, not in spite of it.

Re: A Brazilian CA trusted only by Microsoft has issued a certificate for google.com

#100
post #97

Earlier quoted context omitted.

Can you explain? I think the parent is suggesting that users should be able to tune their trust stores. I'd imagine that trusting only the CAs that are in all the major trust stores (Google, Microsoft, Mozilla, and Apple) would be a reasonable policy. Few websites would choose a CA that falls outside that group.

Users can tune their own trust stores.

Is there a way to do it that isn't tedious? I'm not familiar with tooling beyond the UI browsers offer, which doesn't match the experience I was trying to describe.
Post reply on HN