6 ms·
StartSSL, please revoke me – My private key has been compromised
- Nanzikambe 12y agoTo better understand the stupidity in leaving the power with the CI for SSL/TLS : $ gpg --gen-revoke $(whoami)@$(hostname -f) gpg (GnuPG) 2.0.22; Copyright (C) 2013 Free Software Foundation, Inc. This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. How would you like to pay us? (1) Mastercard (2) VISA (3) Other Your selection? Also, a dark cynical part of me wants to ask exactly what the business model behind "free" SSL certs is? You're not paying them, someone else is?
- jamescun 12y agoOnly their entry level certificate is free, they have higher priced options for the likes of wildcard and EV certificates. Once your root certificate has a good level of acceptance, the true cost of certificates is the validation process; actual certificate generation is negligible, hence certificates with little-to-no validation can be offered at little-to-no charge.
- Nanzikambe 12y agoFair play, now I know. The hand waving wild-eyed long-haired conspiracy theorist in me has been silenced .. for now :)
- jerf 12y agoIf you're interested in security or programming anywhere in the area of TLS, it's worth your time to set up your own CA, issue yourself certificates, figure out how to convince your local browser to accept them, etc. Had I done that myself properly earlier, I'd have some less heartache in my future.
- __david__ 12y ago> Also, a dark cynical part of me wants to ask exactly what the business model behind "free" SSL certs is? You're not paying them, someone else is? Well, you never give them your private key, so… what could they possibly do??
- pritambaral 12y agoWhy is the power of revocations in cert issuer's hands? As long as the private key is private, I don't see how a malicious entity could add your private key to the revocation list. In fact, a place in the revocation list should be reserved every time a cert is issued, possibly with a mechanism to trigger it with the private key. For example, if I send a message encrypted/signed with my private key to the revocation authority, they can decrypt/verify it with my public key, which they received when the CA issued my cert.
- andreasvc 12y ago> Why is the power of revocations in cert issuer's hands? As long as the private key is private Because a major reason for revocation is when the private key has been compromised.
- pritambaral 12y agoSo? Even if the key is in the hands of an attacker, what can they do to the corresponding entry in a revocation list? Add it, nothing else! Unless, you mean that the owner has lost access to the private key itself. For that case, I can see CA's having the power to revoke certs in addition to my suggested method.
- riquito 12y ago>> Why is the power of revocations in cert issuer's hands? As long as the private key is private >Because a major reason for revocation is when the private key has been compromised. His point is that whoever compromised the key is not interested to put it in the revocation list. If he does it... well, he did the good thing.
- andreasvc 12y agoI see. Using the private key to revoke the certificate would be a denial of service attack, so requiring the CA for revocation avoids that, but admittedly it's not the first thing to worry about when a private key is compromised.
- 12y ago
- bananas 12y agoMoney trumps security always. PKI as it stands is fucked up.
- deleted 12y ago[deleted]
- tonylampada 12y agoSo now it's official. They got the evidence that the certificate is compromised yet they refuse to take action. If that's not violation of CA policy I don't know what is.
- achille 12y agoHow dare they give you a free service, and then decide to charge for a revocation which they had said they would charge for (and is meaningless because by default all browsers ignore revocations). Unfortunately for various historical fuckups, we consider self signed certificates to be more dangerous than cleartext unsecured http. Lots of scary warnings pop up. That is absurd. Starcom is helping fix this by issuing free certificates. The Mozilla CA policy does not include a provision for obvious trolling and posturing. If Starcom were to be forced to revoke your certificate for free, why would anyone else (on any CA) ever pay for revocation?
- egeozcan 12y agoI'm also against bashing of StartSSL but they could at least show some good will. "I'm not angry, I'm just disappointed"
- Nanzikambe 12y agoNothing wrong with bashing a free product or service. If I paint two pieces of art, one I let you view for free, the other I charge to view - are you only entitled to an opinion on the latter?
- lstamour 12y agoI thought this post was simply making clear on an example domain what the policy was, and that because of the heartbleed issue, the author had legitimate concerns about the other certs' security. This one was just posted more obviously to prove the point.
- berkes 12y ago> (and is meaningless because by default all browsers ignore revocations) Strange, because when I revoked my cert at StartSSL yesterday (and payed for it), the browser, Firefox on Ununtu immediately showed it as revoked. With a big bold warning when visiting the page.
- lstamour 12y agoI've used these guys in the past and quite like them, but yeah, this is poor PR and I hope they get pulled for not paying attention to, you know, the overall security of the trust product they're selling. I don't want lock-in on my SSL cert but it's effectively a contract if I have to pay a fee to break it and the SSL padlock on my domain is held hostage if I don't. Maybe someone should open a bug report on Bugzilla...
- saurik 12y agoSo, to verify, would you rather pay a (smaller) fee upfront for every registration (effectively, insurance against revocation), rather than pay a (larger) fee if and only if you ever need to revoke? (Or, are you saying that StartSSL is somehow evil, because they refuse to do everything you ever wished they could do for you with no compensation of any kind?) (Is the issue simply that they won't revoke without a fee, even if you don't have your key reissued? I thought that it was just a charge for reissue, but if they won't let you even revoke the key without reissue, then I agree that sucks; but that doesn't seem to be what you are complaining about.)
- lstamour 12y agoHmm. Would I rather pay a fee every year for my domain name or only if I happen to need to change my name servers, contact info or account password. Perhaps more realistically, pay the host before a transfer or early termination. Yes, getting started might be free, but that just makes accidental lock in easier. Life happens, changes happen. Free should be free, is all I'm saying. Makes for a better internet. Maybe browser vendors should offer free SSL certs, or promote pinning self-signed ones somehow? ;-)
- claudius 12y agoNo, they are evil because they are lying to me. When Mozilla put them in my browser, they promised “we will make sure that only people who own the domains get certs for them”. Now there are a bunch of people with leaked private keys and StartSSL is apparently doing nothing about them. Note that I don’t care what StartSSL wants their “customers” to do, nor do I care what these “customers” want StartSSL to do, but I do care about private keys with associated valid StartSSL certificates floating around the internet, and it is not the responsibility of the owners of these keys to revoke the certs ASAP but StartSSL’s. Given that they don’t seem willing to do so, I’ll have to remove their CA from my browser. One easy way out for “free certs” would be a clause like “If we have reasonable evidence that your certificate is compromised, we will revoke it immediately and you agree to pay a handling fee of 25 € for that.” in their Terms and Conditions. If such a clause would be illegal, I guess free certificates are just not feasible.
- techsupporter 12y agoClassic Big Lebowski moment: You're not wrong, you're just an asshole. Their stance is entirely correct. The customer used a file that StartCom provided in software that turns out to have had a security flaw. That's neither StartCom's problem nor liability. They didn't say "use this certificate with anything other than OpenSSL; you'll be sorry if you use OpenSSL," nor could they have foreseen it. On the other hand, showing a cold unwillingness to help when doing so is by far the above-and-beyond response doesn't engender good customer loyalty. It's also how StartCom operates. This is the same cert authority that insisted that I send them a full, unredacted copy of a mobile telephone bill with every "family plan" member's full call, SMS, and data history in order to call me. Otherwise, they could only "verify" me by sending a snail mail letter from Israel to South America (where I lived at the time). Independently-linked, outside verification databases operated by local government entities weren't sufficient. At least they're consistent with their "rules are rules" processes.
- taspeotis 12y agoTheir stance is entirely correct Well it sounds like their stance is wrong if they've agreed to the Mozilla CA Certificate Maintenance Policy: CAs must revoke Certificates that they have issued upon the occurrence of any of the following events: ... the CA obtains reasonable evidence that the subscriber’s private key (corresponding to the public key in the certificate) has been compromised
- andreasvc 12y agoIt doesn't say it needs to be free. It's perfectly reasonable to charge a nominal handling fee, as other CAs do for their services. What's special is that StartSSL offers their basic certificates for free, but this shouldn't make people feel entitled. Especially when someone exposes their private key on purpose they don't deserve special treatment in my book.
- daveasdf 12y ago> CAs must revoke [...] I understand the word "must" to mean that they cannot add additional strings, such as payment, to their obligation to revoke the certificate. Is there another way of interpreting it that I am missing? I guess you could interpret it as "must provide a mechanism", but I can't see that that was the intent of the original document. Mozilla's use of the word "must" here I think is important, because the barriers to correctly dealing with a security breach should be minimized. For better or worse, root CA's are entrusted with maintaining the security of large chunks of the internet. Charging users who suspect that their certificates _may_ have been compromised (due to the Heartbleed bug, in this case) will cause users to err on the side of inaction, which is going to weaken internet security in the long run.
- jrockway 12y agoPersonally, I'd just send a patch to my favorite browser removing their certificate from the trust chain, and then send StartSSL an email with a link to that. Although I doubt anyone will merge your change, it sends a cynical message about how their entire business lives and dies at the whims of people with commit access to the list of trusted CAs.
- paskakapu2 12y agoStartSSL is based in Isreal. They are hungry for money.
- wut42 12y agoLet's admit StartSSL will revoke you. Then what ? Chrome will still don't check revoked certs. Mac OS X neither (and Safari). Only Firefox will...
- claudius 12y agoThat is a critical security flaw in Chrome (and your toy OS there with the fancy graphics). Arguing that someone else made a mistake which renders your mistake unimportant under some circumstances is neither excuse nor justification, in particular not for continuing to make that mistake.
- mitchty 12y agotoy OS? Honestly, grow up. The default in OSX is best effort. Its easy enough to change to require looking at revocations or fail the connection. Anyone that cares about security is going to be looking at what their software does and ensure its configured securely. Not posting on hacker news about a "toy OS there with the fancy graphics" like a ninny.
- lazylizard 12y agoperhaps startssl is thinking about ending their free cert "business", much like how dyn has stopped free dyndns..
- andreasvc 12y agoThere's no reason to think that. This has been their policy all along.
- nly 12y agoMozilla should just spin-off their own CA, pricing the service fairly as a non-profit. It's not like they aren't the gatekeepers anyway. Users don't trust Verisign or StartSSL, they trust whoever Mozilla, Microsoft or Google trust. Stop accepting new CAs in to the browser whitelist, start a CA for the public good with a true open source, full disclosure mentality. Why not?
- mnx 12y agoThat seems kind of like putting all your eggs in one basket. I think the separation of powers is good, even if what it has produced right now is a bad situation.
- nly 12y agoMozilla, Microsoft and Google are carrying the baskets. What you have now is N ways of getting compromised, because even the CAs you don't trust can issue certificates for your domains. To be honest, I'm being a bit tongue-in-cheek. I don't think Mozilla should really do this. I just think people should question this naive belief that the CA industry is out there to help the little guy paying ~$20 for a certificate for their blog or forum.
- e12e 12y ago[semi-cross posted from: https://news.ycombinator.com/item?id=7557764 https://news.ycombinator.com/item?id=7557764] There was an interesting thread on the subject of starting a CA on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg: http://lists.randombit.net/pipermail/cryptography/2013-January/003594.html http://lists.randombit.net/pipermail/cryptography/2013-Janua... http://lists.randombit.net/pipermail/cryptography/2013-January/003609.html http://lists.randombit.net/pipermail/cryptography/2013-Janua... http://lists.randombit.net/pipermail/cryptography/2013-January/003620.html http://lists.randombit.net/pipermail/cryptography/2013-Janua... And for good measure, on the subject of certs and trust, the thread after: "another cert failure" (2011) http://lists.randombit.net/pipermail/cryptography/2013-January/003592.html http://lists.randombit.net/pipermail/cryptography/2013-Janua...
- quasque 12y agoThe author is running a business on the domains he's talking about (a crowdfunding site that takes a 3% fee [1]) so he should just regard it as an unplanned business expense and pay up if he feels it's so important for his certs to be revoked. Not that revocation will have much practical effect on the unlikely event of his keys having been compromised, and an attacker considering his website important enough to MITM - and having the means to do so to a sufficiently large audience to make it worthwhile. Seems like a lot of fuss over nothing much, in this case. EDIT: Also just to note that the private key he has shown on this website was compromised solely by him putting it there, and not extracted via Heartbleed. Indeed, the certificate was created a few days after the vulnerability was reported and fixed. Makes this strange cry for attention even more absurd. [1] https://freedomsponsors.org/faq#How%20do%20payments%20work https://freedomsponsors.org/faq#How%20do%20payments%20work?
- TheHippo 12y agoI never understood why people use StartSSL. Their service is horrible. The interface is far beyond ugly. You could get a SSL certificate in a nice and easy way for 4,99$ at http://www.ssls.com/ http://www.ssls.com/. (They reselling from different CAs. They cheapest one is currently PositiveSSL)
- pritambaral 12y ago> I never understood why people use StartSSL The difference between 4,99$ and 0$. I can bear a slow loading page that I can barely navigate through as long as I can save 4,99$ (or more).
- rythie 12y agoWith StartSSL I've get multiple-domain wildcard (8 domains) cert for $59/year (or 2-3 years if you don't need to change it). This is pretty hard to find in general, and the ssls.com interface does not make it any easier. For example the same 8 domain wildcard Positive SSL Multi-Domain: £360 I could revoke my cert a dozen times a year and it would still be cheaper than anything else I've found - happy to be informed of viable competitors at a similar price though (not necessarily lower) As someone with several side projects (like most of us - I assume) this type of certificate is essential if we are to use SSL at all.
- joesb 12y ago> Starcom's position is very firm and clear (and horrible, and against the security of the internet). [...] I won't be using their service again. Funny the author didn't see it that way when he started using their service.