4 ms·
I don't like this at all. The only value left in WoSign root certificates is in issuing backdated certificates that wouldn't be widely distributed. So basically
by jpablo 10y ago
I don't like this at all. The only value left in WoSign root certificates is in issuing backdated certificates that wouldn't be widely distributed. So basically the only way to extract any money out of their current root keys is to sell rogue certificates for targeted attacks.
- BillinghamJ 10y agoMozilla has explicitly stated that if they find any evidence of this happening, both WoSign and StartCom will be completely revoked - both for old and new certificates. > If additional back-dating is discovered (by any means) to circumvent this control, then Mozilla will immediately and permanently revoke trust in the affected roots.
- jamiesonbecker 10y ago> if they find any evidence of this happening There's already evidence of this happening. It happened. Why does it have to happen again. Just revoke em.
- inimino 10y agoThe point of doing it this way is that it puts the CA out of business but doesn't break the Web, which makes it the only really practical way for browsers to exert leverage over too big to fail CA's.
- lathiat 10y agomore accurately, this way all the existing issued certificates are not invalidated. the idea is not to punish the customers of wosign, startcom who already paid for a certificate and have it in use. if they removed it entirely, those would all break which would be inconvenient to the otherwise innocent customers.
- jamiesonbecker 10y agoYes, of course what you are saying is true, but I feel that this is underestimating the risk of keeping them in the system. Wosign/startcom are known bad actors and put the entire ecosystem at risk because browsers trust all CA's equally. Certificates are ultimately fungible with redundant CA's globally. One certificate is essentially as good as another, from the browser perspective (and nearly all site visitors). This interchangeability: Reduces the risk for 'otherwise innocent customers' in terms of cost (especially now with letsencrypt) so it's "easy" (or at least possible) for customers to replace their existing certificates when they had put trust in an untrustworthy vendor, and Increases the risk that Wosign/startcom will sign bad certificates by backdating them (especially because signing certs is, in fact, their business model and now they have no incentive to not sign bad certs by backdating, since their business is basically dead now anyway.) The risk is too high to NOT revoke all of their certificates, unless the current certs were able to all be enumerated and pinned. Letsencrypt only issues certificates for 3 months in order to provide some semblance of control. If they wanted to have their cake and eat it too, Mozilla could give a thirty or 60 day warning period saying 'upgrade your certs NOW' or change them to 'untrusted' (grey) for that period of time and then completely remove (red) the way Chrome has done in the past with legitimate but no-longer-secure certs.
- inimino 10y agoThey have a pretty strong incentive to not backdate certs after all the attention this has gotten. Distrusting future certs punishes the company, distrusting all of them punishes all past customers and their users, and encourages people to just switch browsers.
- inimino 10y agoThat's what's meant by "breaking the Web": releasing a browser that, from a user's perspective, just doesn't work in some fundamental way. In addition to the inconvenience to site owners and users, it would also lead people to blame the browser if the sites still work in other browsers, which would make it hard for any one browser to unilaterally distrust a CA.