Francisco Partners Acquires Comodo's Certificate Authority Business
eweek.com
eweek.com
Imagine if you had a fool-proof way to murder people, but it requires you leave their corpse in a public square with a copy of your photo driving license and a signed confession. Now, perhaps for some reason you are politically untouchable so you will never see justice. Still though, by this method absolutely everybody will know you did it, so it doesn't seem like a good idea anyway.
All of that doesn't prevent someone from issuing a certificate from a public CA and /not/ submitting it to a CT server: there's no easy way to detect that. If someone did that, though, they would have to present the certificate to your browser without a CT stamp attached. Both Firefox and Chrome are working on implementing mandatory CT validation, at which point your browser will yell and scream if it is presented a cert from a public CA that doesn't have an associated CT stamp. (Right now, if you want to check CT timestamps on certs, you need a plugin (there's one for Firefox, e.g., at https://www.elevenpaths.com/labstools/certificate-transparen... although I can't vouch as to its completeness).) At that point, sneakily grabbing certs from a public CA won't do you any good because it will be obvious they're not legitimately issued.
An interesting problem in this design is how to persuade users that they've encountered something genuinely important that it would be helpful for them to tell someone else about. (Maybe browsers can store such questionable certificates offline and gossip about them to other TLS servers later.) It's not very common for people to be persuaded that errors on their computer matter and that other people will care about them... but this one does! :-)
I know HPKP has a report method which one could imagine generalizing somehow to CT inclusion failures, but, in many attack scenarios involving use of misissued certs, the victim's network connection is controlled by the attacker. In that case, the attacker will probably not want to allow the victim to report the attack to another server in real time.
The article also seems to imply that Comodo is selling its CA business "because of what happened between Google and Symantec." They seem to try to spin it as an opportunity for Francisco Partners, but I wonder why Comodo was suddenly interested in selling its CA business - is it because their infrastructure was just as shake and insecure as Symantec's? Certainly something to think about.
Do nothing in AWS that isn’t hidden, encrypt local and store on Dropbox...
Keybase and similar should be used as new examples of the kind of apps and features to be offering
End-to-end encrypted messaging, git, and file sharing
Am done with Google and the like for personal and soon at work where we’re migrating from AWS and Google G suite
It’s market evolution. Out with Kodak and in with digital cameras.
Only now it’s social media and services 1.0
Since it’s just software it can happen much faster and more frequently
Props to Comodo though for having the foresight to exit while there was still value.
Also: ACME for EV is coming.