Distrusting New WoSign and StartCom Certificates
blog.mozilla.org
blog.mozilla.org
These guys must be joking. Trust has been lost, the roots should be permanently revoked.
If anything, I think Mozilla's actions are not severe enough. How likely is it that Mozilla doesn't know the full story? There may be additional violations that have been missed.
The axe Mozilla is holding over WoSign is the threat of immediate full revocation if WoSign is caught doing backdating again. Given that WoSign has been coerced into cooperating with publishing all CSRs via Certificate Transparency, and that there is likely to be a much larger group of people watching carefully for violations, I don't expect it to take very long for future backdated certificates to be caught if WoSign does try it.
I'm also glad it does not affect existing certs, since we need some weeks to ramp up the LE certs because of the 20 new certs per week limit (we can continue to only bundle subdomains per cert that are actually used on the same host/loadbalancer).
I'm wondering if there's been any progress in finding an easy solution for this use-case.
In our case, there's a script on the frontend machine running HAProxy that's fetching the certificates and putting them on a shared file system so the backup machine also has access to them.
The traffic between frontend host and application servers is unencrypted in our case as it's all one rack under our control. If it wasn't, we'd be using a self-signed certificate for that connection.
> If additional back-dating is discovered (by any means) to circumvent this control, then Mozilla will immediately and permanently revoke trust in the affected roots.
There's already evidence of this happening. It happened. Why does it have to happen again. Just revoke em.
if they removed it entirely, those would all break which would be inconvenient to the otherwise innocent customers.
Wosign/startcom are known bad actors and put the entire ecosystem at risk because browsers trust all CA's equally.
Certificates are ultimately fungible with redundant CA's globally. One certificate is essentially as good as another, from the browser perspective (and nearly all site visitors).
This interchangeability:
Reduces the risk for 'otherwise innocent customers' in terms of cost (especially now with letsencrypt) so it's "easy" (or at least possible) for customers to replace their existing certificates when they had put trust in an untrustworthy vendor, and
Increases the risk that Wosign/startcom will sign bad certificates by backdating them (especially because signing certs is, in fact, their business model and now they have no incentive to not sign bad certs by backdating, since their business is basically dead now anyway.)
The risk is too high to NOT revoke all of their certificates, unless the current certs were able to all be enumerated and pinned. Letsencrypt only issues certificates for 3 months in order to provide some semblance of control.
If they wanted to have their cake and eat it too, Mozilla could give a thirty or 60 day warning period saying 'upgrade your certs NOW' or change them to 'untrusted' (grey) for that period of time and then completely remove (red) the way Chrome has done in the past with legitimate but no-longer-secure certs.
Distrusting future certs punishes the company, distrusting all of them punishes all past customers and their users, and encourages people to just switch browsers.
In addition to the inconvenience to site owners and users, it would also lead people to blame the browser if the sites still work in other browsers, which would make it hard for any one browser to unilaterally distrust a CA.
This is...a big deal? If Mozilla believes E&Y HK was negligent or complicit in WoSign's lies, then that newfound scepticism should extend to the office's financial audits.
They still have the name, so one can only surmise that Ernst & Young stands behind their actions.
https://groups.google.com/a/chromium.org/forum/#!topic/ct-po...
I guess I'm not the best person to criticize other logs, though. :-)
Chrome 54 is now in stable.
They seem to take, at least partially, ownership of the issues. Am I also correct in that this only affects intermediate certificates? I see they say that they will have a workaround in place in about a months time.
[1]: https://www.wosign.com/English/News/announcement_about_Mozil...
No. As the article states, it will affect any certificates that chain up to the specified root certificates (including and intermediate and end-entity certificates).
> I see they say that they will have a workaround in place ...
From previous statements, I believe WoSign's plan is to resell another CA's certificates during the period that they don't have a root of their own in the trust store.
or find/buy another currently trusted CA that cross-signs their new root. I'm sure they can find somebody.
edit: yes. that's what they are going to do according to https://www.wosign.com/English/News/announcement_about_Mozil...:
> There will be new SSL certificates issued by a new WoSign intermediate CA which is signed by the one of global trusted root CA, it supports all the browsers (including Firefox). This will be done within one months.
I wonder who's going to be stupid/reckless enough to sign that intermediate.
But I suspect that another Chinese company or Chinese owned company will be selected to be the signor.
I have my doubts about whether Mozilla will accept them continuing to operate an actual CA with a new cross-signed certificate prior to them completing the inclusion process. CAs need to disclose these intermediate certificates, and I expect it would end up being revoked, with possible sanctions for whoever cross-signs them.
You have a much higher opinion of the probity (and competence) of CAs than is probably warranted.
1. They take no direct responsibility, nor try to explain, or excuse the deception claims. To WoSign, the whole thing is "an incident", not a premeditated deception.
2. They still do not acknowledge their ownership of StartCom, or explain why that was kept in the dark. In fact they keep talking about "4 WoSign roots" despite the 6 roots mentioned by Mozilla.
It seems pretty clear that the future lies in the blockchain.
On a more serious note, Certificate Transparency, which will become mandatory in Chrome in about a year, uses technology that is strongly related to blockchains, so we're really not too far from a blockchain-like solution for the Web PKI.
It's not ready for primetime, and it has its own issues. I don't really see it gaining much traction. But it does present an alternative approach to the problem.
Names should be strong to prevent spoofing but not so strong that squatters and unlawful holders of keys can disrupt their legitimacy.
https://news.ycombinator.com/item?id=12784295
(Certificate Transparency is basically a Blockchain. And this may be one of the few cases where a blockchain-like technology actually makes sense.)
http://www.links.org/files/decentralised-currencies.pdf
He seems to have argued that CT's log works on different principles, although surely it's influenced by all of the revitalized consensus work that's happened after the Bitcoin paper.
At any rate, this gets to the crux of PKI's problem. This was a backdating of certificates because of a change in policy about the cryptographic strength of hashes. But the weak point in PKI isn't the cryptography, it's the agents.
That being said, the risky bit is that they actually signed those SHA-1 certificates in the first place - a certificate that could be specially crafted to "collide" with one for a site an attacker wants to impersonate. It's not really all that important whether they're revoked (though there's nothing wrong with revoking them just in case).
As for CAs being the weak point, luckily we're going to be living in a mandatory Certificate Transparency world in the not-so-far future.