addons.thunderbird.net SSL certificate has expired
thunderbird.topicbox.com
thunderbird.topicbox.com
I wonder if Cloudflare broke this somehow (whoops) or if Thunderbird themselves screwed up here. I don't see a CAA record that would tell DigiCert they can't issue this either.
Resolved, probably?
Okay, is DigiCert having problems today? That's CloudFlare's primary provider, so the LE certificate might be a stop-gap applied by CF.
If Cloudflare gets right to the wire and then is like "Oh, DigiCert couldn't issue for whatever reason" then that's a process problem at Cloudflare not DigiCert.
A reasonable strategy is to renew say, 30 calendar days in advance. But that would mean Cloudflare (or at least, some automated system that nobody was looking at) knew 30 days ago this would happen and nothing was done about it.
I only see certificate issuances from Let's Encrypt.
None of those R3 certificate expire today, and the expired cert I was originally served when this was a fresh news item was from that Cloudflare intermediate CA under DigiCert.
It's possible that normally Thunderbird has Cloudflare trust their backends via the Let's Encrypt certificate rather than using Cloudflare's private "origin" CA for that purpose. That would give them the flexibility to cut Cloudflare out of the loop if necessary. But what exactly happened here I expect we'll learn in a post-mortem.
† I assume but don't know for certain that in fact DigiCert operates this intermediate CA simply on behalf of Cloudflare but entirely on their own premises and with them ensuring its obeys the CA/B BRs and other trust store policies. I think the idea of letting somebody else operate unconstrained intermediates with them doing all the work died out after it sank Symantec.
Seems it was now renewed as a Let's Encrypt one.
Why bother encrypting anything at this point of the connections are going to be terminated somewhere in the network anyway?
Companies have lots of suppliers.
1: https://www.computerworld.com/article/3393446/mozilla-issues...
> "Mitchell Baker, Mozilla's top executive, was paid $2.4m in 2018, [...] Payments to Baker have more than doubled in the last five years."
> "Mozilla recently announced that they would be dismissing 250 people."
It doesn't actually strike me as 'reasonable rate' for a company which is losing market share with their main products, has a history of multiple failed product/service launches, and is having to fire people to cut costs. I (and many others) could get the same results for a mere $700k/year.
Surely, you can see the flaw in this logic though? If you set the salary too low, then only unqualified people will apply, and you'll be guaranteed to get bad results. You have to pay a competitive salary if you want even a chance of getting a skilled leader. Worse, it is harder turn around a company that is doing poorly than to cruise along at the helm of a well performing one. Which means that you both want to have higher standards when selecting a CEO of a poorly performing company, and also have to pay a premium to attract qualified candidates at all.
They have an enormous budget, but are funded from basically a single source, and the future of that funding is not guaranteed.
They have dramatically dwindling market share. This is critical because their voice in the future of the web could easily be drowned out by the interests of Google-Apple-Microsoft.
Their non-browser projects are inconsistently conceived, and unreliably maintained.
These situations have been created and compounded under the direction of their CEO.
They have no roadmap to fix these issues, any of which could be fatal.
Mozilla is our best hope for the future of the free web, and their gross mismanagement makes me very fearful.
Every single year, they are funded well enough to remake the organization, and every single year they do not.
I say this as a loyal Netscape/Mozilla/Phoenix/Firebird/Firefox user since always.
I say this with a continued belief that Brendan Eich created a situation (or a situation was created around Brendan Eich, if you prefer) where he could not have effectively led Mozilla.
And I say this with awareness that 99% of us would probably fail to lead Mozilla (it is a delicate balancing act) -- but that only the current management has dipositively done so.
If there was any accountability to users or shareholders, the Mozilla executive team would have been replaced years ago. It is difficult to watch this astonishing waste of resources, and massive dereliction of duty to the public.
I think Eich was actually lucky, in a twisted way. It's not like he managed to turn their fortunes around while he was their CTO for so long. He wasn't some powerless underdog who would have gained special superpowers as their CEO.
Even if he had avoided controversy to become their CEO, he would almost certainly have just been the one we're scapegoating now instead of Baker. She was our angle when Mozilla was founded and when Microsoft needed an antitrust spanking, and now she's uor devil.
Someone with new ideas should be Mozilla CEO. Someone who believes in the mission of the organization, and will use the organization's vast resources to chart a new path that respects that mission.
An executive search would have no trouble finding quaified candidates at that pay level. They might not work out either. But failing in the same way, over and over, is silly magnified to horrifying due to the importance of Mozilla to the web and the public.
I don't entirely agree about Eich. He was respected in the org, and obviously has ideas that exceed Mozilla's charter. A CTO is limited in their strategic scope, so I don't think his years working for Baker indicate he would fail in the same way she has.
I'm also confused as to why you think an executive search would surely find a better candidate when it clearly hasn't. We can't just pretend the problem away. If we can't find a better candidate than the woman who ran MoCo when it was founded, then we're grasping at straws.
It also doesn't matter whether we want to believe Eich could have done better. He didn't, and he isn't going to be their CEO now. So I'd rather not pick at old wounds too much.
The difficulties Mozilla has had in finding a better direction have a lot to do with depending too much on search revenue, Google now and from 2004 except for the ill-fated Yahoo deal in end of 2014 which blew up in 2017. At Brave, I’ve had to find other revenue than a Google Search deal. I couldn’t have done it at Mozilla, but never mind me: Mozilla can’t find other revenue either, and this probably dooms them as Firefox sheds users while Google pays on traffic (I’m told).
A CEO needs to earn their keep. Baker does not, and somehow keeps getting increases while there are zero metrics on which the organization is improving.
Mozilla has a huge budget, so it's not terribly surprising that some well-paid person is in charge of it.
(Somehow Mozilla's CEO's pay has managed to increase while the organization's budget has been decreasing. This is inexplicable and unjustified.)
Regardless of how well- or over-paid Mozilla's CEO is, though, she is not adding comensurate value to the organization, and I invite her to earn $3MM elsewhere starting tomorrow.
OTOH, if tomorrow she announces The Mozilla Fund, and reveals that they've been accumulating excess budget (tens, hundreds of $MM/yr) into a permanent trust that will support perpetual development of Firefox and related technologies at a secure withdrawal rate -- and that all has been done legally from an accounting and tax perspective, and that we've all just overlooked it in the annual reports ... then I nominate her for Chairperson Emeritus who can keep her stupid salary, and hire a clueful product person as CEO.
Some guy creates a certificate, leaves the company, there is some renewal mechanism which just works, nobody knows anymore where it exactly is and then it starts failing.
Which is why part of the standard operating procedure (SOP) of adding any new service is to add it to your monitoring infrastructure. This includes certificate expiration even if it is supposed to be automated.
Automation breaks sometimes, and you have to know when it does breaks so a 'manual override' can be done.
Contrast stuff like: Did we pay the utility bills? Oh, you thought Jim did it, Jim thought Sarah did it, Sarah thought you did it, and so they weren't paid, and this morning bright and early an engineer from the utility company disconnected our supply, we are dead in the water. Don't worry, your utility company is probably a local monopoly and so they definitely have excellent customer support /s
https://bugzilla.mozilla.org/show_bug.cgi?id=1548973
https://discourse.mozilla.org/t/fixed-certificate-issue-caus...
https://blog.mozilla.org/addons/2019/05/04/update-regarding-...
Let's Encrypt explains their choice for 90day certificates here: https://letsencrypt.org/2015/11/09/why-90-days.html
edit: With 3 year certificates there is also a greater risk for certificates expiring unexpectedly because the renewal process happens so infrequently. The person with the knowledge on the renewal process might not be at the company anymore by the time the certificate expires.
If the certificate is only valid for three months however, many people will automate the renewal right away, because nobody wants to do this manually every couple weeks.
From a security POV, shorter lifetimes require more periodic checks for the server's identity. E. g. a Letsencrypt-issued certificate using the ACME protocol will validate the server really belongs to the given domain more often, which is a nice property I think.
1. Revocation is broken. The obvious way for revocation to work (your browser checks if the certificates it sees have been revoked) not only has negative privacy implications (so e.g. Firefox does not implement this) it also plain doesn't work. It has "fail-open" behaviour for a bunch of sad but inevitable social reasons. In theory we have viable fixes for this, but in practice we can fix really big problems (e.g. a whole CA is compromised) with a lot of effort and smaller problems (e.g. your IT guy emailed your private keys to a scammer) mostly not at all. Thus, expiry is the hard stop, if your certificate expires in six weeks, the scammer loses any benefit [edited] in six weeks. Problem "solved" or at least mitigated.
2. The Web PKI can only evolve at the rate permitted by certificate expiry. Anything faster will set important stuff on fire, because no matter how hard you try you can't publicise changes enough to ensure people are aware of them. e.g. Everybody needed to stop using SHA-1 certificates, that took several years, when the same happened for MD5 it took so long to be effective that even though it was deprecated before a reliable collision was known there were multiple successful attacks anyway. Under Apple's current 12 month rule, if we need to fix something ASAP, we can either break the world, or we wait until late 2022. But under the historic Five year rule that becomes break the world or don't fix it until 2027. That's a pretty big difference in how agile we can be without telling everybody, "Sorry, we broke the whole Internet, reinstall and try again".
Now, I assume that the list of people who visit Porn Hub isn't valuable enough to justify the CA (DigiCert again) explicitly monitoring who visits the site and selling it when they already charge PornHub good money for a certificate. But who knows?
SNI is even more accurate, because things like cloudflare certs are often for 100s of different domains with many wildcards.
eSNI has not really taken off yet, so almost always your requests are saying the exact domain you are going to in clear text.
However, the bit about the CAs getting some analytics about certs they issue is valid.
Setting required to true just makes it actually demand a response instead of allowing an MITM to block it making OCSP ineffective.
At the end of the day we need to start progressively rejecting certificates that aren't OCSP stapled to fix both sides of this, but for now this is the best fix available for technical people who understand how OCSP works.
Yes.
But for the larger global problem, OCSP stapling is a solution in the same sense that "Don't dig up any more coal, oil or gas" is a solution. Yes, I urge you to do this in both cases. It's a good idea. But, is everybody going to do it tomorrow? Next year? In my lifetime?