Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Subjunctive posted:

I can guarantee that your coworker Wayne is not our Wiggly Wonder.

Sounds like something someone would say to throw off suspicion

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






Volmarias posted:

Sounds like something someone would say to throw off suspicion

Is that you Wiggly Wayne? Is this me?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

spankmeister posted:

Is that you Wiggly Wayne? Is this me?

... Is it?

Wiggly Wayne DDS
Sep 11, 2010



anyway there is a discussion brewing, too much to quote https://bugzilla.mozilla.org/show_bug.cgi?id=1890898#c19

spankmeister
Jun 15, 2008






Volmarias posted:

... Is it?

I'm trying to do a bit here

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wiggly Wayne DDS posted:

anyway there is a discussion brewing, too much to quote https://bugzilla.mozilla.org/show_bug.cgi?id=1890898#c19

:prepop:

Ben Wilson posted:

We greatly value everyone’s input because it enables us to engage in informed decision-making. We are considering whether these certificates should be revoked. Are there additional insights and opinions regarding that question? It appears that the certificates complied with industry standards and that the replacement certificates would be nearly identical, except for serial numbers and validity periods. In stating your position, please consider and explain both the potential benefits and drawbacks to the Mozilla root program and the security of the internet. Thanks.

Paul Buonopane posted:

Were this an isolated incident, I wouldn't have a strong opinion. However, Entrust appears to have a history of pushing the limits when it comes to revocation.

Personally, I'm uncomfortable with a CA being allowed to conduct business this way. I have no choice but to delegate my security and trust to these CAs. I rely on the root programs to enforce the BRs on behalf of myself and the rest of the internet.

I see three possible outcomes:


  1. The root programs continue to be lenient with Entrust indefinitely. Nothing changes.
  2. The root programs continue to be lenient with Entrust for a while, but eventually the mistakes pile up enough that one of the root programs pushes for distrust.
  3. The root programs immediately stop being lenient with Entrust. Entrust is forced to make internal changes to remain a CA.

- provides a set of pros and cons for each option-

Conclusion
I'm in favor of enforcing revocation for this incident. It's minimally disruptive, and it nudges Entrust in the right direction while still setting a strong precendent.

Wayne posted:


- continues to demonstrate how Entrust is acting in bad faith via plentiful examples-

:words:

The shield of subscribers being the victims and Entrust trying their best has to stop at some point. The standards of CAs is only held up by the lowest amongst them, and despite working with their subscribers for years we're still getting the 'expire rather than revoke' story until a Root Program shows up. See #1524876 (2019) for an idea of how long this has been in Entrust's playbook - this is a kind example.

... Is it happening?

spankmeister
Jun 15, 2008






Volmarias posted:

... Is it happening?

:pray:

lament.cfg
Dec 28, 2006

we have such posts
to show you




do not sleep on this banger

Raymond T. Racing
Jun 11, 2019

is this the long promised happening

it looks like there’s now Apple, Google, and Mozilla root program managers all with eyes on this mess

spankmeister
Jun 15, 2008






lament.cfg posted:

do not sleep on this banger

number 5 is pretty spicy 🌶️

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Raymond T. Racing posted:

is this the long promised happening

it looks like there’s now Apple, Google, and Mozilla root program managers all with eyes on this mess

nothing is happenable until the root program managers look, soooo

Raymond T. Racing
Jun 11, 2019

Captain Foo posted:

nothing is happenable until the root program managers look, soooo

well all the root program managers are looking

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Raymond T. Racing posted:

well all the root program managers are looking

exactly!

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Them looking doesn't imply happening will happen, only that happening may or may not happen to happen.

Raymond T. Racing
Jun 11, 2019

if it happens, will the happening be a happenstance or pure happenchance,

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Volmarias posted:

Them looking doesn't imply happening will happen, only that happening may or may not happen to happen.

No, but them looking is a prerequisite for distrust to be happenable

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
who was the last root to lose trust like this? it feels like it has been a few years

redleader
Aug 18, 2005

Engage according to operational parameters
5. What are the other Mozilla Root Program rules that don't matter? got an audible lmao from me

SeaborneClink
Aug 27, 2010

MAWP... MAWP!

Lain Iwakura posted:

who was the last root to lose trust like this? it feels like it has been a few years

TrustCor because Rachel McPherson couldn't keep her foot out of her mouth and imploded a CA by being combative in all her responses to CA/B

concerns about TrustCor

https://security.googleblog.com/2023/01/sustaining-digital-certificate-security_13.html
https://support.apple.com/en-us/102798
https://www.sectigo.com/resource-library/root-causes-260-ca-trustcor-deprecated

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Raymond T. Racing posted:

is this the long promised happening

it looks like there’s now Apple, Google, and Mozilla root program managers all with eyes on this mess

did Apple show up?

Raymond T. Racing
Jun 11, 2019

Subjunctive posted:

did Apple show up?

Clint Wilson looks like he’s Apple.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Raymond T. Racing posted:

Clint Wilson looks like he’s Apple.

oh I missed him commenting, nice

I wonder if he and Google Ryan would join a d-s-p thread

susan b buffering
Nov 14, 2016


lol those posts from rachel are a doozy

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

she’s kinda right about CNNIC

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Wiggly Wayne DDS posted:

anyway there is a discussion brewing, too much to quote https://bugzilla.mozilla.org/show_bug.cgi?id=1890898#c19

i'm
    Benefits to the security of the internet
    1. This probably ends in Entrust being distrusted.

gnatalie
Jul 1, 2003

blasting women into space
salivary glands sensing blood

Captain Foo posted:

lol if you think there’s anyone at my company that would understand this except me

shackleford
Sep 4, 2006

lol i had completely forgotten about trustcor, i thought that was years ago but apparently it was like last year?

https://cabforum.org/about/membership/members/

why are they still in the CA/Browser Forum if they aren't in any root stores any more? was it cheaper to pay up front for a 5 year subscription to the CA/BF lol

why are they still posting online about how mad they are over a year later ahaha

https://trustcor.com/news/01262024.php

it's a huge wall of text and i regret clicking Read More but

quote:

Many of you are already aware that certificate issuance by TrustCor ceased in 2022, but in keeping true to our word, we stuck around to help with the transition and remained fully-supported with customer service, certificate status services, world-wide trust and proper technical behaviour for certificates issued before November 1, 2022 through the extent of their certificate life-cycle.

lmao wanting credit for providing customer service for "the extent of the certificate life-cycle". yep, that sure is a 398 day certificate we issued to you in exchange for your money. yep, it's not expired. nope it doesn't work in any browsers lol

shackleford
Sep 4, 2006

updating the blog but not any of the support FAQs i see

https://www.trustcorsystems.com/faq posted:

How long are TrustCor certificates valid?

TrustCor's certificates can be purchased for terms of 1-2 years.

Are TrustCor SSL certificates trusted by all browsers?

Yes. TrustCor SSL certificates are automatically trusted in all current versions of popular browsers including Safari, Firefox, Google Chrome, Microsoft Edge and Internet Explorer. TrustCor certificates are also compatible with the following operating systems: Microsoft Windows, Apple OS X/macOS, Linux, Android, iOS, Windows Phone, Chrome OS.

SeaborneClink
Aug 27, 2010

MAWP... MAWP!

shackleford posted:

updating the blog but not any of the support FAQs i see

Please file an incident for CPS+CCADB not being updated

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

This is the kind of statement that would get me a managerial Talking To were I to say it.

Wiggly Wayne DDS
Sep 11, 2010



so entrust's pr team added themselves to the cc list on the snowballing issue involving ben. i gather they didn't realise that's all public..

anyway only through the pr team inviting themselves did i notice they have a cybersecurity podcast with an episode as recent as 7 days ago. the cert expired april 28th

Raymond T. Racing
Jun 11, 2019

lol and lmao even

Raymond T. Racing
Jun 11, 2019

“should we revoke the certificates?”
“no let’s call PR instead”

Zamujasa
Oct 27, 2010



Bread Liar
prevent revocation

namlosh
Feb 11, 2014

I name this haircut "The Sad Rhino".

Zamujasa posted:

prevent revocation

Public Ridicule

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Raymond T. Racing posted:

lol and lmao even

lomarf, also

Raymond T. Racing
Jun 11, 2019

Probably Revocable

Arsenic Lupin
Apr 12, 2012

This particularly rapid💨 unintelligible 😖patter💁 isn't generally heard🧏‍♂️, and if it is🤔, it doesn't matter💁.


This is leagues outside my area of competence (which isn't that big to begin with). Am I right in reading that Entrust's response to all verified reported breaches of the certificate rules is "Nah, we don't want to"?

Raymond T. Racing
Jun 11, 2019

Arsenic Lupin posted:

This is leagues outside my area of competence (which isn't that big to begin with). Am I right in reading that Entrust's response to all verified reported breaches of the certificate rules is "Nah, we don't want to"?

more or less

edit: they're citing a single paragraph of Mozilla's root program rules that don't really apply, and using that to justify their refusal to revoke.

that paragraph also has no impact on other root programs allowance of not revoking

Adbot
ADBOT LOVES YOU

shackleford
Sep 4, 2006

they are also being real dickish about their "leadership" and how they're completely familiar with the rules and requirements (which is why they should be allowed to break them) and then immediately being shown to have a completely superficial understanding

like the "maybe we will consider establishing a process to review our contact details in the database once a year" thing where another CA piped up with "actually here is the chain of rules that result in requiring your contact details to be kept up to date within 14 days"

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply