Certificate Authorities and the Fragility of Internet Safety
azeemba.com
azeemba.com
But it's not. Microsoft is the only entity that trusts ICP-Brazil. Microsoft cut a deal with Brazil, exclusively regarding software Microsoft controls, to allow them to do... whatever it is they were doing.
You should be unhappy with Microsoft if you're a Microsoft customer. But this has almost nothing to do with the WebPKI. Microsoft could also have rigged their browser up to accomplish the same thing.
- https://bugzilla.mozilla.org/show_bug.cgi?id=1890898
- https://groups.google.com/a/mozilla.org/g/dev-security-polic...
DigiCert incident was pretty loud so that got my attention too: https://bugzilla.mozilla.org/show_bug.cgi?id=1910322
It's all brown M&Ms here.
Which is the correct course of action:
"Of course. Thank you for paying attention to the spirit of the rule."
Or: "No, fuck you, show is cancelled."
---
All of the stuff I said happened did happen. The extra context you are providing is irrelevant since it does not change the fact that what happened is stupid and it's Mozilla's fault that stupid stuff happened.
It's not a certificate intended for use on the web in general. It's an open finance certificate designed for use within that ecosystem within Brazil, and it was issued to a google subsidiary who would have requested it to have that common name, and who would have been evaluated as being authorised to have such a certificate within that context.
The main problem seems to be that the root certificate was in the MS keystores, and seems to have previously been submitted to mozilla (and maybe others) for inclusion, which points to a poor separation of concerns for that CA. They clearly wanted to be a general web authority at some point, but were repurposed.
So it's hard to see it as purely a "misissuance", and it's definitely not malicious.
This can be solved with a certificate authority authority authority.
The first will be named CARTMAN and must be respected by all.
public class CertificateAuthorityFactory{For example, a secondary DNS-based verification layer where a site’s public key is published as a DNS record (though that would likely need DNSSEC to be effective). It seems like it could complement the existing CA structure without replacing it entirely.
I think a DNS layer would probably make that problem worse, not better, which is one of the enduring criticisms of DNSSEC and DANE.
CT[1] allows some kind of external audit, but this is _mostly_ after the fact.
DNSSEC have much worse trust issue.
It's OK not to pay any attention to the WebPKI! It's a whole specialized thing. But that's what you'd have to do to reach the conclusion that "not much has changed". The years following 2012 were the most momentous in the history of PKI.
Do they?
I believe Firefox allows OS-level root CAs in addition to their built-in ones (not sure if that includes OS-provided ones or is limited to local administrator/user installed ones).
Chrome used to defer to the OS-provided one entirely, but it looks like it now has its own store and ignores OS-provided CAs (but does accept admin-provided ones).
Hm, the more I look at this... It seems like they do, these days :) At least the large ones; I doubt that smaller browsers such as Opera, Brave etc. have their own trusted root program.
For example, I do believe that Opera used to have their own (while they were still doing well), but they seem to be using Chrome these days [1]:
> Opera considers certificates presented trustworthy only when they either have a certificate chain that can be validated up to a Root CA certificate included in the Chrome Root Store or a certificate explicitly configured to be trusted by the user.
When I enter some-entity.com, I want to know I'll end up at some-entity's website, even if said entity made some mistakes in the past, like forgetting to renew it [0]. I also want paypa1.com and friends to be down permanently, not to serve fishing pages.
[0] https://www.techdirt.com/2003/11/06/microsoft-forgets-to-ren...
Indeed