3 ms·
Just look at the root program members in the Mozilla program, look at EFF data or the great notary.icsi.berkeley.edu/trust-tree/ As for disclosing all CAs have
by rmhrisk 14y ago
Just look at the root program members in the Mozilla program, look at EFF data or the great notary.icsi.berkeley.edu/trust-tree/
As for disclosing all CAs have agreed to disclose -- no secret here at all.
And clearly from this thread I am being very open :)
- marshray 14y agoThose projects show sub-CAs actually seen in public scans. They don't show all the sub-CA certs that could be used to compromise one's own security. We don't even have any idea what percentage of sub-CAs they show. For example, I doubt they show the TURKTRUST sub-CA that was used in an actual MitM of Google (and likely many others). This is not directed specifically at you @rmhrisk, but it's really disappointing how everyone involved in PKI seems to have a systematic habit of pretending like clearly identified potential risks and vulnerabilities are equivalent to impossible until (and sometimes even after) they're actually caught being used in an actual exploit.
- rmhrisk 14y agoMarsh, I understand your concern and I share it though I don't agree with the conclusion (re sticking head in the ground). With that said GlobalSign has committed to implementing CT and we hope all other CAs agree to do the same as Adam points out earlier in this thread its the way to bring the desired transperancy. That said it alone inst enough either, to start we also need TACK (and/or HSTS pinning), CAA, robust revocation checking and Name Constraints. And while conversations like this are uncomfortable (certainly for me being on the receiving end) I think they help too.
- marshray 14y agoSo are you proposing that 3rd party sub-CAs be brought under public CT? I could get on board with that.
- rmhrisk 14y agoI believe for CT to "work" all CAs on the public internet need to participate. I also believe that certificate transparency by itself is insufficient and the other items I mentioned are also needed.