3 ms·
It gets worse. ICP-Brasil, the AC mentioned in the bug reports, the the government run agency responsible for all things related to digital signatures. Digitall
by cjalmeida 2y ago
It gets worse. ICP-Brasil, the AC mentioned in the bug reports, the the government run agency responsible for all things related to digital signatures. Digitally signing a contract, a deed, accessing tax returns…
- layer8 2y agoUnlike web browsers, digital signature use cases should perform revocation checks, so revoking the google.com certificate should solve that.
- perching_aix 2y agoI think the current "meta" is CAA records? https://blog.cloudflare.com/why-certificate-pinning-is-outdated/ https://blog.cloudflare.com/why-certificate-pinning-is-outda...
- 8organicbits 2y agoCorrect, which Google is using: https://www.nslookup.io/domains/google.com/dns-records/caa/ https://www.nslookup.io/domains/google.com/dns-records/caa/
- syncsynchalt 2y agoCAA records rely on the CAs to respect them, and this is an article about how a CA has issued a cert in violation of a CAA record.
- perching_aix 2y agoOh right, for some reason I was under the impression that browsers utilize the record too.
- lxgr 2y agoThe problem here isn't really that one mis-issued certificate, but rather the general problematic behavior of that CA reported in TFA. If a CA can be convinced to issue a server certificate for google.com, would you feel very comfortable trusting their contract/deed/... signing certificates?
- Muromec 2y agoIf the government says you need to use their CA, you may feel the feelings, but you will still use them
- KetoManx64 2y agoWhat would stop me from purging all this CA's certificates from my computet?
- bawolff 2y agoJust need to DoS the revocation server right before your digital signature is checked.
- justinclift 2y agoSo you're saying it's only a matter of time until they issue a cert for x.com as well? :)