Comodo will just issue you an SSL cert for anyone
blog.startcom.org
blog.startcom.org
What's really fucked up here is that Verisign will never hear the end of it about mistakenly issuing a Microsoft certificate in 2001 --- it was just mentioned again in the New York Times --- but in 2008 Comodo can just mint certificates for random companies without checking, and all it merits is a blog post.
I can self-sign certs. The problem is that no browser recognizes my self-signed certs, so they put up dialog boxes filled with warnings. (Which many users will just dismiss without a second thought, since they are very used to their machines crying wolf. But let's ignore that big problem for now.)
So the problem is that some of the CAs whose credentials are pre-installed and pre-trusted in various browsers or clients turn out to have shoddy verification practices. Does the answer to this involve Mozilla, Webkit, Microsoft et al. decertifying these CAs, which would turn them into the equivalent of someone like me, signing certificates in his basement?
I guess the problem with that is that all the existing paying customers of these CAs would wake up one day to find that their certs don't work anymore and that their money was wasted.
What is the answer to this problem? What kind of contract do you have to sign to become a CA, and with whom?
If you ask me, the biggest problem is that we've acclimated the whole user population of the Internet to ignorance and a cavalier attitude towards security. Companies like Comodo "get away" with stuff like this because people see certificates as a nuisance --- they're a pain to request, a pain to install, and they make browsers complain.
The fact is that SSL simply doesn't work without the PKI component. The PKI component is most of the actual security in SSL. But because technical people get away with saying "even if you're not authenticated, you're at least encrypted", it isn't the end of the world when Comodo (or RapidSSL) screws up.
As for "what kind of contract do you need to sign", what you need to do is convince Microsoft and Mozilla to add you to their root CA store; both organizations have standards and practices, and both incur an audit, and neither are particularly inclined to add more CA's (there's a bit of grandfathering that appears to happen here).
Speaking for myself, the causality flows in the other direction. Because there will always be somebody like Comodo who will issue certs with insufficient verification (Comodo being an extreme but there's been a long history of merely insufficient verification; ISTR a lot of "fax me a letter on official letterhead", which is just total BS), the PKI component of SSL, being basically a binary yes/no system, is fundamentally flawed. Market forces compel a race to the bottom in this situation and there's just no way around it. (Not even moving it to a government function; nobody is immune to having money waved under their nose.) So all you get from SSL is encryption, not authentication. Whether you like it or not.
If you really insist on the dichotomy of "SSL provides either perfect security or no security", then the answer is, it provides no security, because it is impossible to use it properly.* The legitimate owner can do everything right and still get CA-rooted with non-zero (and significant-in-practice) probability.
If that's a problem, get designing and implementing.
* Or, even more precisely, the only proper use is to use a separate communications channel with the website to verify the key they are sending out, regardless of who putatively signed the cert. And this use is a myth in the general case, because I can't imagine more than the barest fraction of SSL sites have ever gotten this query and I bet the majority of organizations would either have no idea what to tell you since you can't talk to the guy who knows (if any), or would even think you were a hacker or something trying to get something from them you shouldn't.
Shuttleworth deserves credit for creating a good company; lots of hard work, for sure. But it couldn't have happened without getting approved my Microsoft. How a young man from Cape Town pulled this off seems to be an untold part of his success story.
Thawte _was_ a success story for its time. When Shuttleworth created it he severely undercut prices which is why Verisign had to buy them since he was quickly working up the food chain. After Verisign bought them, they carefully controlled the product offering to keep it the low-price step-child that it is today.
I have used Thawte a few times but the last few years I have been dissatisfied. Do you have any recommendations? I would like to give my business to someone other than Verisign if possible.
There are operational requirements and management attestations that must be made such as "WebTrust Principles and Criteria for Certification Authorities".
http://www.cica.ca/download.cfm?ci_id=45239&la_id=1&...
The technical stuff starts on page 34. The intro to the document claims that the WebTrust CA standard is loosely based on RFC2527:
http://www.ietf.org/rfc/rfc2527.txt
The technical material in these documents is about FIPS compliance for hardware crypto, key size, and backup/restore; in other words, the exact same stuff you'd read in a Common Criteria document, utterly divorced from actual operational or code security. Compare to the new PCI-DSS standard: on paper, it is actually harder to process an individual VISA card than it is to run a CA.
Neither document contains the letters "M-D-5" or requires serial numbers to be randomized. However, the majority of CAs do randomize serial numbers, suggesting a best practice that simply isn't included in the industry's CA certification standard.
The link you provided to the Bugzilla report on adding GeoTrust/RapidSSL is almost offensive; it reads: "we got audited by KPMG, here's our address", "ok, fill out this document", "ok, we'll add you to the next release".
As long as you purchase your certificate from a CA well placed in the major browser vendors, you're good to go.
Edit: Here's a list of Mozilla's included certificates: http://www.mozilla.org/projects/security/certs/included/
Mike Zusman tested a group of CA issuers and received a cert for Microsoft's live.com and talked about it at Blackhat this year: http://schmoil.blogspot.com/2008/08/domain-validated-ssl-cer...
Additional information at: http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1...
Seems to me, that for most people the presence of SSL is completely meaningless.
Does anyone have any concrete data on the effects of SSLs on sales that comes from a neutral source?
Now, for the research on SSL and UI, there is good research on this. My favorite is The Emperor's New Security Indicators - http://www.usablesecurity.org/emperor/
"We confirm prior findings that users ignore HTTPS indicators: no participants withheld their passwords when these indicators were removed. We present the first empirical investigation of site-authentication images, and we find them to be ineffective: even when we removed them, 92% participants who used their own accounts entered their passwords. We also contribute the first empirical evidence that role playing affects participants' security behavior: role-playing participants behaved significantly less securely than those using their own passwords."
Personally i think the best solution would be SSH style for most sites (the certificate is stored on first visit and changes are flagged as suspicious), with physical distribution of public keys for sites that really needed security (e.g. banks).