5 ms·
Respect to them for actually abiding by the BRs. Most CAs just shrug [1] and [2] say [3] it's [4] too [5] complicated [6], or just lie and claim planes will sta
by devrand 2y ago
Respect to them for actually abiding by the BRs. Most CAs just shrug [1] and [2] say [3] it's [4] too [5] complicated [6], or just lie and claim planes will start crashing [7]. It's really disheartening that publicly trusted CAs just ignore their contractual obligations however they see fit.
Ideally these companies should have response plans in place to prioritize certificate rotation. They can use this as a fire drill for what would happen if there were a key compromise.
Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1885568 https://bugzilla.mozilla.org/show_bug.cgi?id=1885568
[2]: https://bugzilla.mozilla.org/show_bug.cgi?id=1898848 https://bugzilla.mozilla.org/show_bug.cgi?id=1898848
[3]: https://bugzilla.mozilla.org/show_bug.cgi?id=1910237 https://bugzilla.mozilla.org/show_bug.cgi?id=1910237
[4]: https://bugzilla.mozilla.org/show_bug.cgi?id=1896053 https://bugzilla.mozilla.org/show_bug.cgi?id=1896053
[5]: https://bugzilla.mozilla.org/show_bug.cgi?id=1896553 https://bugzilla.mozilla.org/show_bug.cgi?id=1896553
[6]: https://bugzilla.mozilla.org/show_bug.cgi?id=1877388 https://bugzilla.mozilla.org/show_bug.cgi?id=1877388
[7]: https://bugzilla.mozilla.org/show_bug.cgi?id=1903066#c48 https://bugzilla.mozilla.org/show_bug.cgi?id=1903066#c48
- hg35h4 2y ago"Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case." I hate hearing this awful take, as if every IT organization has the same neat and tidy systems deployed as they do. Never had to deal with 3rd party SaaS vendors certificate pinning requiring service tickets to change, don't have any hardware devices or appliance based software images each with their own web interface to update certs... Yes companies should have a plan to do their minimum yearly certificate rotates. Yes those companies should have a security plan to rotate affected certificate issues, but in those cases the business users are ok with an outage to remediate a real security issue. But what happened here is that Digicert invalided the entire domain's worth of certs. All those service.companyname.com certs or duplicates under that domain validation were affected in bulk. In some companies there could be thousands of certs under that domain. Digicert screwed up their system implementation and made their customers suffer. "It's really disheartening that publicly trusted CAs just ignore their contractual obligations however they see fit." It's also disheartening to see browsers in the CA consortium ignore the CA resolutions as well. Like how everyone voted for 2 year certs and Apple did their own thing anyways. Any punishment for Apple come? So why pick on the others?
- devrand 2y ago"Never had to deal with 3rd party SaaS vendors certificate pinning requiring service tickets to change" I think this tends to fall into "probably shouldn't have been using Web PKI". I can't immediately think of a reason why you'd need a publicly trusted certificate if you're pinning a specific public key.. at that point who cares who signed it? I do agree that there are real costs with rotating certificates that ultimately may make it impossible for an organization to complete that work in the revocation window. That is very much an area that needs further automation developed and more importantly, for it to actually be adopted. I believe that's what ACME Renewal Information is attempting to address. "but in those cases the business users are ok with an outage to remediate a real security issue" Ideally yes, but that might be the same point you find out the certificate was used in some critical system (let's say Air Traffic Control like a previous CA tried to claim). They still may very well not be okay with the revocation despite the security issue. _Those_ are the people that need to stop using these certificates and there's really no way to weed them out until a revocation actually needs to occur. "Digicert screwed up their system implementation and made their customers suffer." And those customers are right to be mad at DigiCert. They probably don't have a legal basis to challenge as the subscriber agreement explicitly permits immediate revocation without prior notice, but they can certainly take their business elsewhere. "It's also disheartening to see browsers in the CA consortium ignore the CA resolutions as well. Like how everyone voted for 2 year certs and Apple did their own thing anyways. Any punishment for Apple come? So why pick on the others?" Admittedly I'm not very familiar with the various root programs and the obligations they have with CAs, but it doesn't seem unreasonable that root programs would be free to impose stricter requirements then the BRs. Though I do find it two-faced for Apple to vote for Ballot 193 only to then impose a stricter requirement. At the very least they should have abstained.
- adidas123 2y agoGetting your online account hacked can feel like a punch to the gut. It's unsettling and makes you question your digital safety. But don’t worry! Here’s a roadmap to help you recover your hacked account and get back to feeling secure online. she a tech reach her (MARIECONSULTANCYOZ@GMAIL.COM and INSTAGRAM :MARIE_CONSULTANCY)
- devrand 2y agoSpoke too soon... seems like subscriber(s?) issued DigiCert a Temporary Restraining Order to not revoke: https://bugzilla.mozilla.org/show_bug.cgi?id=1910322#c8 https://bugzilla.mozilla.org/show_bug.cgi?id=1910322#c8 Bold.