5 ms·
Given WoSign's history of backdating SHA-1 certificates in violation of Mozilla's rules, I wouldn't be too surprised if they reuse that practice to get around t
by oxguy3 10y ago
Given WoSign's history of backdating SHA-1 certificates in violation of Mozilla's rules, I wouldn't be too surprised if they reuse that practice to get around the 1 year ban, at which point Mozilla will have to consider permanently distrusting them.
- nandhp 10y agoThey've already considered it and are including this in their proposal: > WoSign/StartCom could back-date certificates to get around this restriction. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.
- Paul-ish 10y agoWould they do this out of spite? StartCom is essentially done for and has little to lose, so out of bitterness they could try to turn their customers against the browser vendors.