Live data from Hacker News

Remediation Plan for WoSign and StartCom

groups.google.com

1–10 of 54 posts

Re: Remediation Plan for WoSign and StartCom

#3
post #2

So they are actually kicking out StartCom as well. Is this new? Apple was quick to move to kick out WoSign but they seemed to keep StartCom around. https://support.apple.com/en-us/HT204132

Mozilla's discussion started with startcom as well as wosign, as they share ownership and shared significant amounts of infrastructure.

Re: Remediation Plan for WoSign and StartCom

#4
post #2

So they are actually kicking out StartCom as well. Is this new? Apple was quick to move to kick out WoSign but they seemed to keep StartCom around. https://support.apple.com/en-us/HT204132

I read about that before. StartCom is owned by WoSign now and there's evidency they completely moved to WoSigns infrastructure.

Re: Remediation Plan for WoSign and StartCom

#6
post #2

So they are actually kicking out StartCom as well. Is this new? Apple was quick to move to kick out WoSign but they seemed to keep StartCom around. https://support.apple.com/en-us/HT204132

I believe so - they're owned by the same company and it wasn't disclosed properly leading to some trust issues.

Additionally there seems to be a lot of co-mingling between the companies in regards to code bases and signing practices.

I'd check out https://wiki.mozilla.org/CA:WoSign_Issues and look for "StartCom" for examples.

Re: Remediation Plan for WoSign and StartCom

#9
post #2

So they are actually kicking out StartCom as well. Is this new? Apple was quick to move to kick out WoSign but they seemed to keep StartCom around. https://support.apple.com/en-us/HT204132

Yes, the Startcom roots are included in the set to be distrusted. Mozilla is allowing Startcom to re-apply sooner than Wosign, but both will have to go through the entire CA vetting process again, and Startcom will also have to prove it's no longer controlled by Wosign.

Re: Remediation Plan for WoSign and StartCom

#10
post #8

Just curious about the root certificate distrust--are users capable of re-adding trust to distrusted certificates? Or is this hard coded into the browser? I'm assuming Mozilla stores certificates outside OS stores like Keychain and Windows?

In general, locally added roots are trusted above all else -- and will even override cert pinning on most systems. Thus, if a user were to manually re-add the Wosign or Startcom roots to the local Mozilla trust store, they would continue to be trusted.
Post reply on HN