5 ms·
If they do that, Mozilla, and most of the other browser vendors, will immediately revoke and blacklist that CA. There was already a lot of debate about adding
by lambda 13y ago
If they do that, Mozilla, and most of the other browser vendors, will immediately revoke and blacklist that CA.
There was already a lot of debate about adding the CA, but the final consensus was, I believe, "as long as they don't actually abuse it, we should trust them; as soon as we have evidence of someone doing a MITM attack with that CA, we will blacklist it".
- dspeyer 13y agoHow many legitimate websites use that CA? Especially ones Chinese users will visit often? If the browser blocks the CA, those will all break. Perhaps the browser could do something subtler, but it's not straightforward. Or we could make the https cert protocol more flexible, but changing protocols is hard.
- gcr 13y agoSourceforge and friends are known for injecting badware into binary installers for open-source software. It will be interesting to see if the Chinese government makes their own alterations to the Firefox binary installers that pass through their network that add the CA back in. Nobody checks their installers' GPG keys anyways
- justin66 13y ago> Sourceforge and friends are known for injecting badware into binary installers for open-source software. Wait... what???
- gcr 13y agoGIMP no longer distributes binaries on sourceforge because sourceforge's installer "bundles third-party offers with Free Software packages. We do not want to support this kind of behavior, and have thus decided to abandon SourceForge." http://www.gimp.org/ http://www.gimp.org/ http://www.gluster.org/2013/08/how-far-the-once-mighty-sourceforge-has-fallen/ http://www.gluster.org/2013/08/how-far-the-once-mighty-sourc...
- justin66 13y agoAfter reading that it doesn't look to me like they're sneaking into otherwise pure installers or doing it without project's knowledge. "When SourceForge introduced this, it bribed encouraged the top projects to participate by giving them a cut of the take. So these co-operating projects are also knowingly selling their users down the river." For as long as I can remember Sourceforge's usability has sucked. That's reason enough to avoid it (but omg! free file hosting!) but the installer thing maybe isn't quite as deceptive and malwareish as your first message let on. It's just another facet of their lameness. Kudos to Gimp for dumping them. Why does anyone stay with them at this point?
- gcr 13y agoAha, thanks for the clarification. It's good to know SF is only doing this under the consent of project leaders; I was under the impression that they were sneaking it under the radar.
- malandrew 13y agoI've actually been disappointed that downloading Firefox is only done over HTTP and I didn't see where SHASUMs for the builds were available. I actually tweeted at them about this and never got an answer: https://twitter.com/andrewdeandrade/status/400001230916694016 https://twitter.com/andrewdeandrade/status/40000123091669401...