5 ms·
I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.
by jhugg 10y ago
I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.
- geofft 10y agoHow could you design a system that works otherwise? Computer security is always about "this key says", not "this legal entity says".
- zokier 10y agoCertificate is more than just a key. Especially EV certs are pretty close to "this legal entity says". CAB forum could have made a policy that root CAs are non-transferable and should remain in complete independent control of the entity that created it.
- andy_ppp 10y agoPeer review and regular key rolling should be built into the system. It should not be based on "root" certificates rather something more like blockchain for generating security keys and each roll /session generates a new key. IANAEE but if building a currency is possible without it being possible to create fake money then it should be possible to protect websites in a similarly decentralised way.
- zokier 10y agoWe have peer review in current CA system in two forms; Certificate transparency being the more visible one, CAB forum operating more in the background.
- jonknee 10y agoWell you could do something like have browser vendors require a legally binding document that the ownership of a CA cannot change without notice (at which point they can reassess the CA). Not that hard actually since there are only a few browsers that matter.
- wmf 10y agoWoSign/StartCom got a bit of a smackdown about their stealth acquisition so there is some level of oversight.
- deleted 10y ago[deleted]
- goodplay 10y agoOnly because they made the mistake of sharing their infrastructure (hence, their quirks) and got caught. I wouldn't call that oversight. CAs should be required to announce ownership or large administration changes, and trust in said CAs should be revoked upon change unless/until they have been re-audited.
- rmhrisk 10y agoThat is effectively how both the Mozilla and Microsoft programs root store programs works.