3 ms·
Comment by the author (from the last time this happened) seemed helpful: "OP here. Unless you work for a certificate authority or a web browser, this event wil
by ryanwhitney 3y ago
Comment by the author (from the last time this happened) seemed helpful:
"OP here. Unless you work for a certificate authority or a web browser, this event will have zero impact on you. While this particular CT log has failed, there are many other CT logs, and certificates are required to be logged to 2-3 different logs (depending on certificate lifetime) so that if a log fails web browsers can rely on one of the other logs to ensure the certificate is publicly logged.
This is the 8th log to fail (although the first caused by a bit flip), and log failure has never caused a user-facing certificate error. The overall CT ecosystem has proven very resilient, even if a bit flip can take out an individual log.
(P.S. No one knows if it was really a cosmic ray or not. But it's almost certainly a random hardware error rather than a software bug, and cosmic ray is just the informal term people like to use for unexplained hardware bit flips.)"
-https://news.ycombinator.com/item?id=27731210 https://news.ycombinator.com/item?id=27731210
- vivegi 3y agoI have no knowledge of how the CAs maintain the CT logs. What is the process for a CA to rebuild the CT log, if one exists? Is it something like what is illustrated below? Let CA1, CA2, CA3 and CA4 be different certificate authorities. The set enumerated alongside each CA is the set of certificates logged into its CT log. CA1 : {c1, c2, c3} CA2 : {c2, c3'} CA3 : {c1, c2} CA4 : {c1, c3} Suppose CA2 is where an issue was detected with certificate c3 (the anomalous cert is denoted by c3') and CA2 trusts CA3 and CA4, then the set {c1, c2, c3} can be constructed after verifying the CT logs of CA3 and CA4 and merging their logs. Is that kind of how it would work or would CA2 just truncate its log and restart from this point forward?
- detaro 3y agoThe broken log will just be replaced by a new one.
- agwa 3y agoThere's no merging or rebuilding. You just nuke the bad log, and certificates continue to work because they are present in other logs. (If all the logs used by a certificate go bad, then you'll have a bad time. This hasn't happened in 5 years of mandatory CT.) The log operator may choose to stand up a replacement log. The new log will have a different key, URL, and name from the old log. It's for all intents and purposes a completely different log.
- vivegi 3y agoThanks. So, the consequence is that browser vendors and other who utilize CT should ignore this log and use whatever is stood up as its replacement. That makes sense.
- pmontra 3y agoCosmic rays are common. There is a detector exposed to the public in the Toledo metro station at Naples, Italy. It's placed 40 meters underground. In this short video you can see 2 cosmic rays passing by https://www.youtube.com/watch?v=K_puq6U7khg https://www.youtube.com/watch?v=K_puq6U7khg