Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BlankSystemDaemon
Mar 13, 2009



zero knowledge posted:

and that’s exactly what’s interesting here: isn’t it a big honking conflict of interest for one company to run both a CA and a root program? — not just that but THE most powerful root program that de facto runs trust on the web
alphabet is entirely a conflict of interest in that they both make money on google adsense (it's the thing they make most of their money on), and own google chrome which they're making much worse at blocking ads.

they're also the originators of quic which has language that's designed to let them make tracking people much easier - and it's already being used plenty and will be adopted more, because it has some of the best features of sctp, while not requiring a complete rework of internet infrastructure.

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



okay made the larger analysis public: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/J3aX8OKIT_A/m/xB723PIsAQAJ

Raymond T. Racing
Jun 11, 2019


also appreciate your summary of entrust: "refusing to revoke in violation of BR and their CPS"

really making it clear what's going on there

EssOEss
Oct 23, 2006
128-bit approved

Antigravitas posted:

It's not going to happen over some typos or missing fields that aren't critically important, but I can absolutely see the EU deciding that having rogue and evidently unaccountable CAs trusted on its infrastructure is not in its interest…

step 1 is to mandate that browsers deployed in EU countries shall include government CAs in trusted roots. once you have that, "do we really need the others" is just a small step away. the wheels are in motion

Cybernetic Vermin
Apr 18, 2005

Antigravitas posted:

The real question in my mind is the implication for the self-governance model if an organisation just refuses to be governed by it. If CAs can just ignore rules without consequences, there will come a point when a nation state or supranational organisation will decide that the model isn't working.

It's not going to happen over some typos or missing fields that aren't critically important, but I can absolutely see the EU deciding that having rogue and evidently unaccountable CAs trusted on its infrastructure is not in its interest…

yep. i don't think it is any exaggeration that the self-governance is on permanent thin ice.

that probably means both that things will have to at least *appear* to work better than this, and, very unfortunate for the entertainment value of the thread, that just cold turkey distrusting can't really happen. like if the self-governance breaks a bunch of poo poo it probably starts being discussed real hard if that is how things should continue, even though the action itself was by the rules.

shackleford
Sep 4, 2006

redleader posted:

booooring

the people want, nay, crave blood

spankmeister posted:

after 600+ and counting posts of this poo poo there had better be some blood at the end

i lust for CA death

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Honestly, I just want a walking corpspeak generator to actually experience consequences for only spewing bullshit instead of attempting to solve problems or (heaven forbid) admit that they made a mistake

Zamujasa
Oct 27, 2010



Bread Liar

Xakura
Jan 10, 2019

A safety-conscious little mouse!

Lolling at this thread, especially this post

psiox
Oct 15, 2001

Babylon 5 Street Team

Midjack
Dec 24, 2007



Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



:respek:

lament.cfg
Dec 28, 2006

we have such posts
to show you





buddy, they won’t even let me revoke certs

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Loezi
Dec 18, 2012

Never buy the cheap stuff

compuserved
Mar 20, 2006

Nap Ghost

FlapYoJacks
Feb 12, 2009

spankmeister
Jun 15, 2008







sitting in the tram at 11:20 pm Saturday evening laughing out loud at this post getting weird looks from my fellow passengers

TheMathyFolf
Sep 14, 2014

spankmeister
Jun 15, 2008






can we make an image the thread title?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

spankmeister posted:

can we make an image the thread title?

Goddamn do I wish. Someone can at least update the OP.

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

namlosh
Feb 11, 2014

I name this haircut "The Sad Rhino".

please help, my family is dying…

revoke the certs

No

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

namlosh posted:

please help, my family is dying…

revoke the certs

No

stop spending so much on being an active participant in the ecosystem and advocating to your customers for certificate agility

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

lament.cfg posted:

buddy, they won’t even let me revoke certs

EVGA Longoria
Dec 25, 2005

Let's go exploring!

IF THE CAB DISTRUSTS ME FOR CONTINUING TO ISSUE CERTS I WILL FACE GOD AND WALK BACKWARDS INTO BANKRUPTCY

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
pre:
D E C E R T I F Y   Y O U R S E L F   A N D
F A C E   T O W A R D S   B U G Z I L L A

redleader
Aug 18, 2005

Engage according to operational parameters

Volmarias posted:

Honestly, I just want a walking corpspeak generator to actually experience consequences for only spewing bullshit instead of attempting to solve problems or (heaven forbid) admit that they made a mistake

Midjack
Dec 24, 2007



Volmarias posted:

Honestly, I just want a walking corpspeak generator to actually experience consequences for only spewing bullshit instead of attempting to solve problems or (heaven forbid) admit that they made a mistake

gnatalie
Jul 1, 2003

blasting women into space
░R░E░V░O░K░E░D░░C░E░R░T░S░░I░N░░B░I░O░

shackleford
Sep 4, 2006

gnatalie posted:

░R░E░V░O░K░E░D░░C░E░R░T░S░░I░N░░B░I░O░S░

Raymond T. Racing
Jun 11, 2019

gnatalie posted:

░R░E░V░O░K░E░D░░C░E░R░T░S░░I░N░░B░I░O░

EVGA Longoria
Dec 25, 2005

Let's go exploring!

gnatalie posted:

░R░E░V░O░K░E░D░░C░E░R░T░S░░I░N░░B░I░O░

please file a bug for non-conformance with the TLS BRs

brains
May 12, 2004


actual lol

Wiggly Wayne DDS
Sep 11, 2010



oooh part 3 is up: https://webpki.substack.com/p/entrust-considered-harmful-part-3

Wiggly Wayne DDS
Sep 11, 2010



notable highlights i think should be noted in there imo

Wiggly Wayne DDS posted:

2020-08-12: Entrust: Invalid data in State/Province Field
- um they found 6 more cert problems in 2021-04-13 but just kept it to this comment? (no issue found when searching uhhhh)

2020-09-27: Entrust: Failure to provide a preliminary report within 24 hours.
- lmao Matthias already did a breakdown of policy fuckups over 2 years ago

2020-10-23: Entrust: Subscriber provides private key with CSR
- took 4 days to revoke after noticing the private key material was compromised...

The Fool
Oct 16, 2003



I love these, thank Amir for writing these up in a public place. This is a lot more shareable in professional environments than this thread.

Adbot
ADBOT LOVES YOU

The Fool
Oct 16, 2003


Wiggly Wayne DDS posted:

2020-10-23: Entrust: Subscriber provides private key with CSR
- took 4 days to revoke after noticing the private key material was compromised...


lmao

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply