Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Wiggly Wayne DDS
Sep 11, 2010



Raymond T. Racing posted:

wait, is the implication here that they don't actually agree with the consensus (on the 5 day max revoke time), but didn't give enough of a poo poo to argue it?
you're starting to understand why that line is so batshit, yes

Adbot
ADBOT LOVES YOU

well-read undead
Dec 13, 2022

skipped 600 posts, was that all about entrust still? lol

Main Paineframe
Oct 27, 2010

Raymond T. Racing posted:

wait, is the implication here that they don't actually agree with the consensus (on the 5 day max revoke time), but didn't give enough of a poo poo to argue it?

i think they just don't want to commit to either agreeing with the rule or disagreeing with the rule, since both would look pretty bad for them

pretty sure they just mean "we didn't really give a poo poo about it either way at the time", but they don't want to just come out and say that directly

fins
May 31, 2011

Floss Finder

well-read undead posted:

skipped 600 posts, was that all about entrust still? lol

tl;dr amir made an account

Raymond T. Racing
Jun 11, 2019

go get em amir

https://bugzilla.mozilla.org/show_bug.cgi?id=1890898#c18

quote:

Well this sounds like you have a reason to be against it now. I would like to note that, even if you disagree with this rule now - that rule is still in effect here and you are in violation of it.

Based on this incident response, it seems like you have no intention to follow the revocation requirements section of the BRs. Am I correct in my understanding there?

Entrust is currently in complete violation of the baseline requirements. Since this incident doesn't even have a timeline for revocation at all, I'm going to assume that Entrust plans to continue being in complete violation of the baseline requirements.

Are there any other parts of the baseline requirements in which Entrust has decided they won't comply with anymore?

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Wiggly Wayne DDS posted:

wtf are entrust doing

it looks to me like they're betting that they can just bullshit their way through this and eventually it'll go away


from my perspective they are blatantly not engaging in good faith. i get not wanting to act hastily, hell i've been guilty of dragging my feet on something like that myself, but at this point the very fact that they've led everyone around in circles for so long in and of itself should be sufficient reason to distrust them



edit: lol i was too slow to post, looks like amir's really had it

digitalist
Nov 17, 2000

journey into Kirk's unknown


Main Paineframe posted:

pretty sure they just mean "we didn't really give a poo poo about it either way at the time and thought opposing it would look bad but ultimately we're gonna do whatever the gently caress we want anyway"



:hmmyes:

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.




:yossame::sign:

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
Goddamn, Entrust's behaviour is rage inducing.

I have to work around people sandbagging at work sometimes, but I've never had to deal with an entire institution just loving around in obvious bad faith.

Raymond T. Racing
Jun 11, 2019

now I’m a moron, but I think at this point they’re at the “we know what the BRs are, we just don’t care” phase which seems not ideal.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

yeah, that was the point I made in my big comment: this cannot be an education gap, given their statements on the topic in the past. it’s a motivation or capability gap, which will be much harder to resolve

Raymond T. Racing
Jun 11, 2019

at what point does GTS or Mozilla root trust look at this and go “hmm I think we need to reconsider”?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

a very very timely question

Raymond T. Racing
Jun 11, 2019

Subjunctive posted:

a very very timely question

do you know something we don't

mystes
May 31, 2006

Raymond T. Racing posted:

do you know something we don't

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Raymond T. Racing posted:

do you know something we don't

my bitkeeper master password, I hope

but no, not on this topic. I’m trying to find out, though

zero knowledge
Apr 27, 2008

Raymond T. Racing posted:

at what point does GTS or Mozilla root trust look at this and go “hmm I think we need to reconsider”?

gonna be pedantic here, not to pick on you but to highlight something I think is interesting about the politics of the web pki

you say “GTS” but Google trust services is not the issue. the Google chrome root program is the entity that might distrust Entrust. you might say “cmon dude they all are at Google it’s the same poo poo isn’t it?”

and that’s exactly what’s interesting here: isn’t it a big honking conflict of interest for one company to run both a CA and a root program? — not just that but THE most powerful root program that de facto runs trust on the web

the answer is yes, yes it is. now Googlers will tell you that while GTS and Chrome enjoy a good working relationship, there do exist meaningful firewalls between them such that there isn’t a conflict of interest here. or, uh, 😅 an antitrust concern. and if we soberly look at the actual history of involvement of GTS and Chrome employees in the web PKI, we observe that they do broadly act transparently and honestly in what appear to be the best interests of the web and the safety of its users. even where they misstep (unilateral imposition of CT) it’s obvious that the motivation was safety of humans on the web. seriously, major props to all the cats and Ryans at Google who have judiciously walked the tightrope of raising the bar on web safety while serving their masters at Google enough to keep getting paid.

but stilll. it’s hosed that it works this way. it’s hosed that the web pki is basically modeled on the UN Security Council. it’s hosed that Google gets to not just call all the shots with 0 accountability (except for ~ market forces ~ someday reducing Chrome’s share of the browser userbase) but also be a player in the market that they de facto regulate.

this thread has been edging for days on the sense of POWER it’s enjoying from the perception of being part of a posse bringing entrust to justice. and that rocks, I love to see people getting invested in collective governance of critical infrastructure. just, I dunno, keep working on your analysis of the power structures and dynamics at play here.

Midjack
Dec 24, 2007




excellent

aaomidi
Apr 16, 2024
This might be helpful, but technically because of this, GTS doesn’t get a vote in the CAB forum.

Also, there should be some attention on Apple and Microsoft here too. Apple has been somewhat active, but Microsoft is just crickets. Both of these entities also operate a root program.

Their lack of participation is something I plan to write about in the future.

zero knowledge
Apr 27, 2008
while you’re at it, consider arguing that Apple and edge start running CT logs

Raymond T. Racing
Jun 11, 2019

point is I hunger for more drama and the only drama left is entrust in a ditch

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

regardless of everything else, the implicit (nearly explicit) admission that they don’t care about the rules seems to be worth distrusting because they have all but said you can’t trust us to follow the rules because we don’t want to follow the rules

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Captain Foo posted:

regardless of everything else, the implicit (nearly explicit) admission that they don’t care about the rules seems to be worth distrusting because they have all but said you can’t trust us to follow the rules because we don’t want to follow the rules

"what are you going to do, distrust us?"
— quote from entrust

redleader
Aug 18, 2005

Engage according to operational parameters

Raymond T. Racing posted:

point is I hunger for more drama and the only drama left is entrust in a ditch

[thread spectators chanting] blood! blood! blood!

Quackles
Aug 11, 2018

Pixels of Light.


redleader posted:

[thread spectators chanting] blood! blood! blood!

Come now, they're a digital organization. They're not made of blood.

[chanting] bits! bits! bits!

SIGSEGV
Nov 4, 2010


I'll be damned before I start trying to figure out what they consider worthy of revoking and make statistics about it, but I'm actually interested in what those numbers would look like.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

aaomidi posted:

This might be helpful, but technically because of this, GTS doesn’t get a vote in the CAB forum.

Also, there should be some attention on Apple and Microsoft here too. Apple has been somewhat active, but Microsoft is just crickets. Both of these entities also operate a root program.

Their lack of participation is something I plan to write about in the future.

MSFT used to be active (enough to force EVERYONE to, roughly), I wonder what happened

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
this is all pretty funny because i have nothing to do with it. well not pretty funny. slightly amusing. mostly just tiresome

if i did have anything to do with it i would probably politely but firmly ask people to shut the gently caress up, give the leadership a chance to work out a response, and stop coordinating on offsites to ramp up the stakes for drama cred

but this is web governance so that’s presumably off the table

The Fool
Oct 16, 2003


why are you a stick in the mud

redleader
Aug 18, 2005

Engage according to operational parameters

rjmccall posted:

stop coordinating on offsites to ramp up the stakes for drama cred

booooring

the people want, nay, crave blood

EVGA Longoria
Dec 25, 2005

Let's go exploring!

rjmccall posted:

this is all pretty funny because i have nothing to do with it. well not pretty funny. slightly amusing. mostly just tiresome

if i did have anything to do with it i would probably politely but firmly ask people to shut the gently caress up, give the leadership a chance to work out a response, and stop coordinating on offsites to ramp up the stakes for drama cred

but this is web governance so that’s presumably off the table

lol at this when it's in like year 5 of this poo poo from entrust

EVGA Longoria
Dec 25, 2005

Let's go exploring!

like don't touch the poop but loving lmfao at "just give leadership a chance to handle this"

Shame Boy
Mar 2, 2010

the leadership had that entire span of time to cook up a response between when the first ticket was opened and when google took notice of it and they realized they actually had to bother with responding now that Someone Important was paying attention

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

rjmccall posted:

stop coordinating on offsites to ramp up the stakes for drama cred

:nallears:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

this stuff is always “coordinated in offsites”

the Mozilla root program public discussion itself was described in similar “oh they’re just stirring up poo poo” terms at the beginning of CA/B, in fact, with similar “leave it to the grownups” dismissal

the reason that bugzilla is the center of this stuff, and the bugs aren’t made private or closed to new-account posting, is exactly because the most active root programs consider themselves accountable to the broader web public

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Subjunctive posted:

this stuff is always “coordinated in offsites”

the Mozilla root program public discussion itself was described in similar “oh they’re just stirring up poo poo” terms at the beginning of CA/B, in fact, with similar “leave it to the grownups” dismissal

the reason that bugzilla is the center of this stuff, and the bugs aren’t made private or closed to new-account posting, is exactly because the most active root programs consider themselves accountable to the broader web public

thanks for the color on the middle paragraph, and making clear what seemed evident just by watching the discussions

spankmeister
Jun 15, 2008






after 600+ and counting posts of this poo poo there had better be some blood at the end

Cybernetic Vermin
Apr 18, 2005

rjmccall posted:

this is all pretty funny because i have nothing to do with it. well not pretty funny. slightly amusing. mostly just tiresome

if i did have anything to do with it i would probably politely but firmly ask people to shut the gently caress up, give the leadership a chance to work out a response, and stop coordinating on offsites to ramp up the stakes for drama cred

but this is web governance so that’s presumably off the table

i broadly think it'd be better if there is *not* blood at the end of this, but what makes it interesting (as opposed to an incredibly mundane discussion about form validation) is that it really doesn't make that much sense as a system if one goes "lets just sit silently and leadership will get back to us", as obviously the system is a hair of bureaucracy and formalia away from just being "google tells us what to trust" already

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
After how many years should we assume that "leadership" has had a chance to address this?

Adbot
ADBOT LOVES YOU

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
The real question in my mind is the implication for the self-governance model if an organisation just refuses to be governed by it. If CAs can just ignore rules without consequences, there will come a point when a nation state or supranational organisation will decide that the model isn't working.

It's not going to happen over some typos or missing fields that aren't critically important, but I can absolutely see the EU deciding that having rogue and evidently unaccountable CAs trusted on its infrastructure is not in its interest…

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply