3 ms·
What's the practical difference between operating their own root and potentially mismanaging it, versus buying a wildcard cert and potentially mismanaging that?
by gnu8 9y ago
What's the practical difference between operating their own root and potentially mismanaging it, versus buying a wildcard cert and potentially mismanaging that?
edit: to answer my own dumb question, the major issue is that Blizzard or someone who steals Blizzard's root CA private key would be able to impersonate any domain they wanted, instead of just Blizzard's.
- hrrsn 9y agoBuying a wildcard cert means they can mismanage their keys for *.battle.net. Having a CA means they can mismanage any domain.
- wyldfire 9y agoI think you understand what having a Root CA means but you haven't clearly explained what "mismanage any domain" means in real terms to folks who don't know these details. It means that employees of Blizzard (hopefully not many of them but who knows) can now create certificates that will be accepted as "Wells Fargo" when the user tries to go to "https://wellsfargo.com" https://wellsfargo.com". Their browser will show the green icon because the browser relies on the Root CAs in the trust store. I think/hope this will break for HSTS sites like most banks. I also think this was likely not intended maliciously by Blizzard. But it's incompetent and opens up unnecessary risk.
- chacham15 9y agoNot just that, blizzard themselves could pretend to be Google.