3 ms·
1) Nope, as evidenced by the fact that we just had one existing root CA booted out due to apparent links to spyware (Trustcor) and a second CA applying with lin
by kseifried 4y ago
1) Nope, as evidenced by the fact that we just had one existing root CA booted out due to apparent links to spyware (Trustcor) and a second CA applying with links to spyware (BJCA.cn) that may or may not make it in.
2) As I've said, CA's should be above reproach. A CA involved in any way with spyware has a clear conflict of interest that can (and has) resulted in major security problems for users (e.g. MitM interception).
Also a lot of this gets worse the more you look:
Asking HOW we are supposed to review these documents and confirm that the auditor is indeed a valid auditor, for example results in, well, no answer. Examples:
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/LnkB0S0ndbM https://groups.google.com/a/mozilla.org/g/dev-security-polic...
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/5v_hynxRfl8 https://groups.google.com/a/mozilla.org/g/dev-security-polic...
- ethbr0 4y agoOn 1, I was thinking about the opposite: a potentially-valid CA (probably a smaller one) that has some unclear paperwork, that someone pieces together a narrative about, with the intention of getting them booted. On 2, agreed on the above reproach. But defining that across international and multiple legal jurisdictions, corporate structures, ownership structures, etc. seems... complex. And honestly, not something I'd trust myself with (as a primarily-SWE). And the external audits don't attest to corporate structure, do they?
- kseifried 4y ago1) If that's the case they should be able to prove they are legitimate without to much effort. If a CA can't prove they are legitimate, well. Err.. they probably need to be booted then. 2) Correct but there are also many CA's that have managed to do a good job here. Why should we allow poorly behaved CAs in when it affects potentially billions of devices and people? As for the external audits correct, they are very narrow in scope, there are also no requirements around change of control (e.g. company A buys an existing root CA).