Jeremy Rowley resigns from DigiCert due to mass-revocation incident
bugzilla.mozilla.org
bugzilla.mozilla.org
Also, as noted in the comments, it sets a bad precedent for people coming forward reporting issues.
accountability at the top is a good thing
Bugs happen, and he's doing exactly what's expected of a leader in this situation. Anyone who thinks "this incident is personally my fault because I didn't read every line of code the devs who work for me wrote, and for this dishonor I am now unfit to lead" is a sane reaction to these events is not living the blameless postmortem life.
Captains used to go down with their ships. In most organisations, this is no longer the case, because we lost all the captains willing to do so, without replacement.
Resigning when you fail to prevent an incident rarely helps, directly. But it's not something the power-hungry do, unless forced (and if they expect to be forced, they will try to cover things up). It rarely fails to win my respect. As a move in a social game, I suspect that the general strategy "resign when an unacceptable failure has occurred" makes things better, overall, even if it doesn't directly benefit the organisation you're leaving. (I'm not sure whether this applies when you don't expect that your replacement feels the same way about duty.)
You have much power, but little as well because every department claims security is the reason their projects are delayed - or if they move quickly and there is an issue, they point back at CISO.
that it were self initiated
* Does replacing the CISO actually make the system more secure? Presumably he had a lot of tribal knowledge built-up and who is going to know the system better than him?
* As systems get more and more complex, it's likely impossible for a single individual to truly understand and prevent these types of situations 100% of the time. It seems that any application that needs to be 100% secure (if that is even possible) has to be provably secure in a strict mathematical sense, which goes beyond individual culpability.
* Does shooting the person accountable actually encourage responsible disclosure or discourage it?
Wherever the bar is, it won't be 100%. That's why good leadership invests in the ability to respond well to mistakes that will inevitably be made.
This replacing the leadership is always the right response.
Counterintuitively, probably yes. Tone flows from the top down, and if you want to change the tone you need to start at the top. It's very difficult to try and build a coalition to change the system from underneath.
Presumably he had a lot of tribal knowledge built-up and who is going to know the system better than him?
Likely he has a lot of political influence and knowledge of the system and for lasting change all of that has to go. If it has gotten that bad it's no good and needs to be swept away.
Much of it at that level is NOT architecture and software discussions. You wouldn't think the job would be similar to lead counsel, but unfortunately a majority of a certain company's risk now a days is in that area.
Disagree entirely. Shit happens, and it’s important to accurately report things going on. Sure someone could interpret this as “we should fire the people who make mistakes” but I think it’s unrealistic to begin with and if it were to happen people would see through it.
It usually happens when people up the ladder want to shrug off their responsibility completely. Loser mentality.
Don't condemn people until you have all the facts, which multiple reporters are working on figuring out right now.
Those processes and policies are set by someone.
From his resignation:
> This incident made me realize that I am no longer the person for this role.
Seems reasonable.
I also find it ironic to discourage this because of the precedent it sets. That’s making him responsible for things out of his control.
Honestly, I can understand that. I can respect it too. I can imagine the stress over that period of time being very high. Personal attacks, business attacks, mounting legal issues from business _partners_. We work in computers sitting on our ass. We are not used to these stressful events. This was probably Jermey's _stress test_ and he unfortunately broke.
I just hope he finds another gig or maybe starts up something on his own. I would probably follow him.
I think the key phrase you are missing which is repeated many places in the timeline is “Engineering was not consulted”. His failure wasn’t that he doesn’t know the entire system, it was that he kept engineering in the dark, “investigated” on his own, and made conclusions to disregard the persistent researcher who kept banging at the door saying “there is an issue” despite him disregarding it again and again, notably without consulting engineering.
You don’t need to know the entire system as CISO, but you certainly do need to know that you don’t know the entire system as CISO. This wasn’t an institutional failure, it was a personal failure at a very high level.
I’m not arguing that the guy had to resign, merely pointing out that the narrative used to argue against his resignation is flawed.
“When DigiCert has another incident (and while I have tremendous faith in Tim, it will happen), I would rather that they have Jeremy Rowley with his wisdom and scar tissue around to guide their response and subsequent improvement.”
This could happen to anyone, but imagine being the developer or development team that made this mistake.
wow that is an extreme level of ownership. the debate of the resignation and the chilling effect it might lend to the incident report itself is also interesting.
Really does sound like he personally dropped the ball in the handling of the report. It would be interesting to hear the story from the researcher who will undoubtably have been frustrated beyond reason that they kept acting like there was no issue despite the repeated persistent attempts at getting them to take it serious.
Unless it's malice, or the fault truly is entirely on that person, what good would resigning do?
Rowley admitted he fucked up, badly, he admitted on several layers what must be changed. How he must change. How the org must change. How the way things are presently is not good enough. Made an extremely deep dive into what happened.
And now he's leaving??? Someone who royalty messes up, would not want to mess up on the same issue twice. So all that experience is now worthless and doesn't benefit Digicert in the slightest.
This seems crazy to me. In what world does suing your business partner make more sense than clicking some buttons in a UI or running some shell commands to renew your cert?
Is UNITES > UNITED a typo? Would that cause any weird legal consequences, or are typos (if it is a typo) like this just accepted?
Deploying to all devices at once relieved the timing problem, but has its own set of problems. Ask the crowdstrike customers.
Now, this could be the fault digicert's customers, but suing to block revocation would be logical.
One could even get fancy and use verifiable randomness for everything in the protocol that is supposed to be random.
And then one could refactor some other code with much less worry about messing up.
This might also reduce the blast radius from a bug in some other component. If the magic random string generator can be coerced into returning ‘www’, then a separate check would prevent this from compromising everything.
(I work in a different industry, and in my industry there is plenty of complex, evolving code, that needs to do the right thing. The more competent players have separate verification code as a double-check.)
How can it make economic sense to initiate a lawsuit rather than just get new certificates?
Probably cheaper to file for one TRO than defend yourself against cases from a bunch of your own customers.
I mean, cheaper still to not contractually obligate yourself to something you can’t guarantee or perform, but once you’re already in that position…
It's a rare incident where a C-level executive actually takes accountability for their fuck up. Shit rolls down hill. He is very likely to end up taking the helm at another place or startup on his own. He is the exact opposite of the CrowdStrike CEO (George Kurtz) that caused an absolute shitstorm compared to DigiCert incident.
Interesting. What is the value of a microservice that generates random numbers over just using a language's SecureRandom equivalent?
I'll leave this in case some find the links interesting:
For someone like DigiCert I imagine they could ensure a much higher quality source of randomness, ie multiple different hardware sources like the avalanche noise of semiconductor junctions[1], cosmic rays[2] or lava lamps[3].
It's also easier to ensure the random numbers used are of good quality when you have a single source, ie you can collect statistics as they're served.
[0]: https://bugzilla.mozilla.org/show_bug.cgi?id=1910322#c17
[1]: https://ieeexplore.ieee.org/document/10295491
[2]: https://nyuscholars.nyu.edu/en/publications/muon-ra-quantum-...
[3]: https://blog.cloudflare.com/lavarand-in-production-the-nitty...
This is what real accountability looks like, and doing so not only preserves the reputation and trustworthiness of his employer, but demonstrates that he is a valuable contributor and trustworthy individual. He will land on his feet as a result.
In this case, a sophisticated attacker can get certificates for domains they don’t control by abusing this.
Even if one would, I very much doubt that a company which argued it has a free speech right to break your website with 24 hours notice would survive the ensuing controversy.
Resigning is what you do when you are clearly not fit for your post. Jeremy has demonstrated that he is anything but unfit. People that can see where things went wrong, who can communicate such, can come up with changes to fix those issues, and can implement them are exactly what is needed at such a high level of management. Most people would bury the story or claim ignorance, but Jeremy doesn't hide anything and takes full responsibility.
I wish Jeremy could have stayed and used this honesty and insight to make the necessary changes. Firing a C-level executive when things go wrong doesn't fix anything any more than finding a low level engineer to blame and fire. Experienced people learn lessons by making mistakes. It sucks that it happens, but unexpected circumstances can't be foreseen. Hindsight is 20/20. Now that they know, they know to look out for it and to change the system to prevent it next time.
Perhaps he did overlook it. Perhaps he didn't respond when he should have. It's easy to get complacent. This is a wake up call. I have no doubt that he would be much more attentive and responsive as a result of this, and as such, be exactly what's needed for his post.
Mistakes don't call for sacrifices; they call for systematic changes to prevent making the same mistakes again.
Thank you Jeremy for being as forthcoming as you have been. I only wish more C-level execs would do the same. I hope you find a good place to land where you can take this experience and do an even better job. And I hope that whoever replaces you can bring the same rigor and professionalism that your brought.