4 ms·
A clear and detailed report. The conclusion seems both transparent and fair. It would be very difficult for many customers of StartCom/WoSign if they were imm
by no_protocol 10y ago
A clear and detailed report. The conclusion seems both transparent and fair. It would be very difficult for many customers of StartCom/WoSign if they were immediately revoked. Hopefully this news spreads far enough that the reputation of StartCom/WoSign will generally include this information.
I am saving this as a reference in the event I ever need to write a technical report. This style is so much easier to read than a typical "official" report from police, the FBI, or similar organizations.
I don't have any StartCom or WoSign certificates right now, but I did in the past. It was nice to be able to get a certificate that browsers accepted, without needing to pay for it. I'm glad the landscape has changed.
- TorKlingberg 10y agoYes, we are very fortunate to have Let's Encrypt now.
- justinclift 10y agoOne problem - at least for the project I'm working on - is that Lets Encrypt isn't a replacement for all of StartCom. We use a StartCom "MS Authenticode" certificate to sign our releases, so Windows users don't get a warning message from the various anti-malware scanners (and similar). At first glance it sounds like Mozilla not accepting new StartCom cert's at some point won't affect that. It may snowball, but that's an unknown. o_O
- aroch 10y agoNSS can forcibly set trust bits for certificate chains -- so in theory they could set the codesigning only trustbit. ButI'm pretty sure Windows is not using NSS as its truststore for those checks. So its up to Microsoft to deal with the de-trusting (which may or may not be modular, I have no idea).
- deleted 10y ago[deleted]
- edwinyzh 10y agoSame here, I've just recently obtained a "Class 2 Code Signing" certificate from StarCom for digital sign my Windows software - as a individual software developer from China, I don't even have alternative options - I tried purchasing from Comodo, but unfortunately there process for checking individuals from out out of the US is extremely difficult. So I wish this would not affect the certificates StarCom issued for code signing.