Windows Certificate Manager does not display the complete trust list
hexatomium.github.io
hexatomium.github.io
certutil -generateSSTFromWU roots.sst
Then open roots.sst (which defaults to viewing in certmgr) and it will show the whole lot. Or use certutil -syncWithWU to get all the certs individually.Alternatively: download http://ctldl.windowsupdate.com/msdownload/update/v3/static/t... [1], extract the authroot.stl file (which is in PKCS#7 format), use 'certutil -dump' to list all the subject key identifiers therein, and then download them from the same location as authrootstl.cab by appending ".crt" to the identifier.
Windows is not lying about anything, you just need to look in the right place.
Also, if you want to examine the CTL list that Windows is currently using - which should be identical to the one above unless it's brand new or there has been a problem downloading it - this will extract it from the registry:
powershell -Command "[IO.File]::WriteAllBytes('authroot-local.stl',(Get-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate').EncodedCtl)"
Then use 'certinfo -dump' or whatever you like, it's exactly the same format as the downloaded authroot.stl. This is the same registry data that the OP's CTLInfo tool examines.[1] as specified in https://support.microsoft.com/en-us/kb/2677070
Latest documentation for this seems to be for IE 5. I sure as hell like to run dkpkg-reconfigure ca-certificates every once in a while after some roots get compromised and don't trust Microsoft to be on the ball.
For example, using the root discussed in the article:
1. Download the root cert from http://ctldl.windowsupdate.com/msdownload/update/v3/static/t... (or save it from the browser's certificate viewer)
2. Open certmgr and import it into 'Untrusted Certificates'.
(This just adds it for the current user's store. Could also import into the computer store by running mmc, adding the Certificates snap-in, and specifying 'Computer account' as the target.)
3. Restart browser. Go to https://certplusrootcag1-test.opentrust.com/ - it should say the certificate is revoked.
This only works for browsers like IE and Chrome, that use the Windows certificate store. Firefox has its own so would have to be done separately.
Edit: I'm referring to configuring the package as ca-certificates is installed or via dpkg-reconfigure
Microsoft's approach means that the user would have to go find the certificate on the internet and blacklist it explicitly, which allows a small window where the computer is vulnerable to some kind of attack involving a certificate signed by the unwanted authority.
https://blog.mozilla.org/security/2015/04/27/removing-e-guve...
edit: e-Guven is being removed "due to insufficient and outdated audits" and not a compromise (Couldn't reply below).
So yeah there are two or more places where certificates are stored. Typical users only care about the abstraction of web security so that's what Windows surfaces. Application developers should choose the new store for new applications. Existing applications can use the old method. System administrators and security consultants should make themselves familiar with all the documentation and double their rates.
Bloggers, however, are still free to write linkbait headlines using the Windows bashing meme.
Typical users do not open certmgr.msc
Perhaps that could be written off as my failing in not knowing what certmgr.msc "should do", but Windows certainly does not make it very clear and I think it's reasonable for an average power user to assume that it shows all the trusted certs on the system, and not part.
that would require specific knowledge about the CA ecosystem and who is trusted. hardly anyone knows that.
And while Microsoft does simplify UIs for end users, they don't typically do the same for administrative content (just look at anything in the Admin Tools, or MMC snap-ins, no sugar coating there).
Your argument about backwards compatibility is at best confusing. What does the data stores utilised have to do with UI representations of the same? I can name numerous examples where things changed behind the scenes and the UI was just updated to support it (e.g. Disk Manager now supports ESP, and exFat, same UI, ConHost now supports Powershell, same UI, Defrag now supports Trim for SSDs, same UI, etc).
> So yeah there are two or more places where certificates are stored. Typical users only care about the abstraction of web security so that's what Windows surfaces.
No, it doesn't. As the blogpost clearly shows it doesn't "surface" all root CAs usable by websites.
> Application developers should choose the new store for new applications. Existing applications can use the old method.
Huh? What do application developers have to do with this? I don't see the connection. This isn't talking about the custom root CAs you may install, it is talking about Microsoft's list of preinstalled ones.
> System administrators and security consultants should make themselves familiar with all the documentation and double their rates.
Please link to the documentation about this on Microsoft's site.
> Bloggers, however, are still free to write linkbait headlines using the Windows bashing meme.
Aside from the word "lying" (which is emotive), the title is largely accurate. Windows does mislead about installed trusted root CAs. And nothing you've said in this apologist answer has come close to addressing that, you're just dancing around it.
"The negative connotation of that word is the implication that you are bound and determined to defend some position and will not be moved — stemming from its roots of defending literal dogma. People take it to mean a sort of closed-minded, blind tribalism."
> And nothing you've said in this apologist answer has come close to addressing that, you're just dancing around it.
I said the answer was apologist, not the individual.
I myself post apologist answers all the time (justifications for controversial positions), but I don't consider myself an apologist broadly speaking. I also don't presume that the above poster is an "apologist" even if I do consider this singular post "apologist" in nature.
"Apologetic" has connotations of regret. I think this confusion might lead some people to take "apologist" as a derogatory or inflammatory word, when it shouldn't be.
https://en.wikipedia.org/wiki/Christian_apologetics https://en.wikipedia.org/wiki/Apologia
And I don't think it's the connotations of regret that lend the term "apologist" its negative connotations. The negative connotation of that word is the implication that you are bound and determined to defend some position and will not be moved — stemming from its roots of defending literal dogma. People take it to mean a sort of closed-minded, blind tribalism.
At any rate, if you don't trust your audience to read "apologetic" in the proper sense, I certainly wouldn't hold out much hope for a neutral reading of "apologist."
I think you are personalizing the debate in exactly the way you are supposedly trying to avoid. Let's debate the facts, not hurt feelings. Nobody has been rude here (at least in the few posts I read). There is nothing wrong with calling someone an apologist, as long as it is done in a respectful way and not just to get a rise out of someone. We don't need to shrink the space for debate here any more than it already has been.
> a person who offers an argument in defense of something controversial.
Is it just me, or are the majority of online communities that I visit becoming overrun with people that get offended by the slightest amount of bold or confrontational behavior?
Objectively speaking, there is pretty strong evidence to support a belief that a "Windows bashing meme" exists to the extent that any meme can exist. Apple spent most of a decade and several billion dollars on buying over the air advertising for it's "I'm a PC campaign"; it's so socially acceptable to bash Windows that PG hisself engaged in it for many years; and a lynchpin of Silicon Valley mythology is NetScape got hosed even though it unicorn exited at about $10 Billion, Marc Andreesen's minority stake was enough to make him a VC and Jim Clark bought a gridiron football field length yacht.
It's not that I'm opposed to over-enthusiastic headlines, well written headlines should capture the reader's attention to the point that they click. What makes it "linkbait" to me is that it panders toward confirmation bias rather than encouraging curiosity: it's us-versus-them tech gossip of the sort that tends not to make people smarter. I often wonder about unicorns not seen because of YC's historical attitude toward Windows [e.g. the days when a tock processor announcement for the mid-year Macbook dominated the HN frontpage for a day or two].
As to the other topic, one form low quality HN comments [1] take is what I call "the internet pick apart". Break a post down into many sound-bites. Cast each into an unfavorable context. Then arbitrarily argue against each sound bite. The goal is to broaden the flame war across many fronts without creating a concentrated target for coherent rebuttal. The pattern is to apply it recursively to each of successive defence by the victim. The sport is to keep the target spinning [there are extra points for reintroducing sound-bites from higher in the thread].
That said, a comment that literally begins with the string "The problem with you" probably isn't intended to produce constructive dialog. Pig lipsticking it with "r argument" doesn't change the purpose. Credit where credit is due, at least the comment works its way up to the pick apart rather than down to the problem with me.
Anyway, whenever I find myself writing or saying "you" in a conversation I try to stop and try to rephrase. It's loaded. When I read comments that use "you" it's usually the rest of the internet seeping into HN. The exception is things like "You can safely assume that I didn't write this on mobile."
[1]: On the other hand, the internet pick apart and other forms of flaming and trolling and pointless arguing constitute some of the highest quality writing on the internet in general. Trolling and flaming are successful because they are writing for an audience and for entertainment and for the shear joy of writing...or at least it was for me.
Here are a few:
http://social.technet.microsoft.com/wiki/contents/articles/3...
Mailing list: https://cabforum.org/pipermail/public/2015-August/005847.htm...
http://social.technet.microsoft.com/wiki/contents/articles/1...
This is just a UI failure.
[1]: http://social.technet.microsoft.com/wiki/contents/articles/1...
Precisely. Windows comes with a small number of roots pre-installed. I can't remember which they are, I assume it's probably just Microsoft's own, one of which is presumably used to check roots fetched later. When you browse the web with a browser that uses Windows's certificate store, it'll fetch other roots as needed.
Interestingly, this might be a security benefit. If you'd never visited a site using a revoked root, you never had the root in the first place.
https://cabforum.org/pipermail/public/2015-August/005847.htm...
How difficult it is to hijack the link between the local and remote certificate stores? That's a potential attack surface. It's not hard-coded; it's a registry key (Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate). The default URL is "ctldl.windowsupdate.com".
So what protects that domain from being hijacked via DNS poisoning? It ought to have a valid SSL cert, right? Well, no. Go to "https://ctldl.windowsupdate.com/":
ctldl.windowsupdate.com uses an invalid security certificate.
The certificate is only valid for the following names:
a248.e.akamai.net, *.akamaihd.net, *.akamaihd-staging.net,
*.akamaized.net, *.akamaized-staging.net
(Error code: ssl_error_bad_cert_domain)
Uh oh. Am I missing something, or are root certs downloaded over an unsecured channel? CTLInfo is the result of a few sleepless nights spent
understanding and reverse engineering some of the CTL
obscure format
I wonder what the reason is to use a userunfriendly system like Windows and then spend hours and hours fighting it?No matter how much time you put in, you will never win against an OS that is working against your interests.
2) Because people are used to it.
3) Because Office products are the de facto standard, and they run best on windows.
I could go on, but you get the point.
Google docs is a much simpler system, especially for places like schools because of the "cloud" nature of it. Google docs has all the features the average person needs.
MSWord is for specialty cases, google docs and the open alternatives are for everyone else.
I'm about to earn a masters degree and I've never needed to use MS word. Double spacing, page numbers, and aligning text work in just about every processor. I've rarely received a word document from a professor that used advanced features of word, they're always poorly formatted.
Thankfully all my documents have very light formatting, so I can just write in Vim and then upload them.
If I copy something else from the same Word document into the same Google Doc, then Google keeps it in Times. How does that work?
Is there a "smart paste" feature I've missed?
I can try clearing the clipboard between pastes: would that make a difference?
One feature I personally needed and missed was to generate a table of contents with page numbers for each heading. I ended up exporting the doc to Word to do it, and in the process discovered that the exported document had a messed up layout in a few places.
About the "features average person needs" remember that users adapt their workflows to the featuers you give them and make do, not the other way around. Give them more, they'll use more.
I think you could probably add "resource hungry" to your description of GDocs....
Orphaning of content: GDocs will very happily strand a section header at the bottom of a page, dropping a page break right between the header and the content.
The cursor will occasionally just go where it pleases.
Revision history (compared to diffing git commits) is incredibly frustrating. Click on a revision, read the whole doc, repeat…
As a sibling says,
> Oh and typography.
For me, google docs works well enough... I use the sheets more than the docs actually, as I keep track of my current bills with it. All of that said, there are a lot of tiny features in MS Office that LO doesn't have.... I don't need them, that doesn't mean that nobody does. I know plenty of people that can't give up their use of excel or word in favor of LO.
I also would love to see a fully free/open solution that works as well as Exchange+Outlook ... I've seen lots of alternatives and options, none are nearly as clean or well integrated. And for that matter, most are a bitch to setup/maintain on the server-side of things, or simply aren't actually free, there's usually a critical "plugin" that's only available with a support contract.
With the exception of printers. Omg printers are such a PITA on windows I often just send a pdf to me and print it with the phone.
Now getting a new printer (new hardware) installed in Linux isn't usually so easy.. unless you're using a fairly mainstream HP Laser printer, which is actually what I recommend because it's so straight forward. Outside of that it's almost always a pain. My current printer is rigged up and connected to print from my phone from anywhere, I have it setup for remote printing via Chrome... which is kind of nice, ordering something, or paying a bill on a break at work and being able to print at home.
Unless you're using a really off brand, I haven't had trouble installing on windows via the add printer... it may take a while to download a full device list for printers, which aren't pre-installed, but that's time not difficulty.
I used to have it on a dns reserved ip but damned new telco router doesn't have that option since I upgrades to fiber.
Every time the epson setup wants to restart the whole computer to start the detection and it is so annoying, I just let any other airprint device do the thing.
I usually just set all mine in the router, but as you said, that doesn't work for you.
Because senior management forces workers to use it.
I'm a scientist who analyzes large data sets. I also need to communicate to my co-workers. I need a secure operating system without a lot of eye-candy that makes it look like a tablet and lets me give priority to my data analysis tasks. Windows is not it, but I have to use it.
I just don't get how we still allow closed source operating systems for critical business tasks.
If you were to poll corporate user income and their provided OS, you will likely find that 99% of workers earning low wages (i.e. not trusted by their companies) are provided windows, the more someone earns the more likely they are to have a choice in OS from their employer--just my hypothesis.
Maybe I'm a bit behind the times, but some collection of VM, MVS, OS/390 aka zOS, CICS, IMS, DB2, RACF, SNA, Oracle, SAP etc etc is probably running the majority of America's critical business tasks. Did it all get open sourced when I wasn't looking?
Needless to say, Google Docs and Gmail are not open source either....
Yes, and that's because it is a very powerful marketing tool for Paul Graham's huge YC business.
Did I miss anything?