China Internet Network Information Center accepted as a Mozilla root CA
lwn.net
lwn.net
Firefox: Tools > Options > Advanced > Encryption > View Certificates > Authorities > find and delete the CNNIC entry
IE: Tools > Internet Options > Content > Publishers > Trusted Root Certification Authorities > find and delete the CNNIC entry
Chrome: Wrench > Options > Under the Hood > Manage Certificates > Trusted Root Certification Authorities > find and delete the CNNIC entry
Note, removing it from either Chrome or IE will remove it from both.
[Edit: added instructions for Chrome and IE]
[Edit: At least this is the case on Windows. File a bug report as sandGorgon suggested if that's not the case.]
I'm more than a little leery about this, but at least if there is a security breach due to this, it should be traceable, right? I mean, if a CA signs a faulty certificate, their signature is part of the certificate, so it should be traceable. So, without any evidence of wrongdoing, how are they any worse than Verisign? Or any of the cheap SSL certificate providers? It's not like the CNNIC is going out of business anytime soon.
Given the demographic of Firefox users, I think that this could end up being a huge PR problem for Mozilla.
Edit: After some checking, CNNIC is a root CA in both Windows and Mac, so I don't think that there was much avoiding this for Firefox.
I am vaguely aware of MITM attacks: that someone sends you their public key while pretending to be someone else. And this means the data you send is encrypted in a way that the MITM can see.
However, I'm unsure how CINIC's inclusion in Firefox's root certificates facilitates this. Perhaps I'm not the only one?
This means if, unknown to you, CINIC impersonates a domain which uses SSL, and you visit that domain and assume your SSL connection will be safe from prying Chinese officials, you're incorrect. Incorrect because Chinese officials could have created that bogus SSL certificate, and it would be accepted by Firefox because Firefox now accept CINIC as a root authority.
Any confirmation, in case I'm spreading inaccuracies, would be appreciated.
As mentioned, CNNIC's inclusion only allows a Man In The Middle Attack. That is, CNNIC, i.e. the Chinese government, pretending to be a site they're not, and using their status as a Firefox (and other) -authorised root certificate provider to further trick the user into accepting the bogus SSL certificate as originating from the hijacked domain.
If your employer uses Watchguard firewalls, they can proxy SSL connections, replace the SSL certificate with one signed by the firewall, and act as a MITM to filter and report the connection contents. If your employer has pushed out certificates by, e.g. active directory and group policies on Windows, then the site will appear padlocked without warnings and you will be none the wiser unless you inspect the certificate. I'm assuming other firewalling products can do similar.
For anyone looking to do manufacturing in China, this is something to consider.
Mathematics aside, the basic concepts are not that difficult. (E.g. chain of trust) Let the users know what's behind the padlock icon; they'll pick it up.
(Oh, and stop making https calls from http pages that ask for security information. The paradigm of "look for https in the address bar" and "the closed padlock icon" was a good start. Then everyone went and started breaking it.)