TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mozilla moves to distrust the TrustCor CA

198 pointsby jamespwilliamsover 2 years ago

5 comments

jwilkover 2 years ago
Earlier today: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33810755" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33810755</a> (40 comments at the moment)
评论 #33814214 未加载
KingOfCodersover 2 years ago
The thread is hilarious.<p>The accused being passive agressive to essentially the judges is mind boggling.<p>I also like how the TrustCor person in the discussion claims the spyware was by a rogue developer and they can&#x27;t do anything about that and gets the reply from the initial poster:<p>&quot;This same rogue developer set up a proxy to receive data sent by the SDK and then forward it on somewhere else. This involved compromising one or more machines owned by TrustCor. This compromise went undetected by TrustCor&#x2F;MsgSafe for 3+ years.&quot;<p>This compromise was undetected by the CA for 3+ years. Q.E.D.<p>And from Google [Edit: was Mozilla, thanks] &quot;I tend to agree at this point that discussing the merits of the claims might be superfluous, because the conduct of the CA&#x27;s representative is a more urgent issue [...]&quot;
评论 #33814760 未加载
评论 #33823651 未加载
评论 #33815190 未加载
评论 #33815010 未加载
评论 #33814469 未加载
pedrovhbover 2 years ago
Seems reasonable to me. Although it&#x27;s not ideal to distrust without a &quot;smoking gun&quot;, it is (as pointed out) inadmissible for any ties to exist between a CA and a malware company.<p>Seeing how a closer look by Mozilla, Google and Apple into publicly available data quickly turned up more points of suspicion, I wonder how much scrutiny is put into CAs in general, and whether it&#x27;s enough. Mozilla currently lists 148 trusted certificates [0] (soon to be 145, with TrustCor&#x27;s departure).<p>[0] <a href="https:&#x2F;&#x2F;ccadb-public.secure.force.com&#x2F;mozilla&#x2F;CACertificatesInFirefoxReport" rel="nofollow">https:&#x2F;&#x2F;ccadb-public.secure.force.com&#x2F;mozilla&#x2F;CACertificates...</a>
BurnGpuBurnover 2 years ago
Certificates are broken anyhow, we might as well do away with them all together. How am I ever able to research, verify and in the end trust all the hundreds of certificate providers out there? Answer: I don&#x27;t, nobody does, and that&#x27;s why it will never work. What&#x27;s wrong with SSH&#x27;s encryption, btw? Can&#x27;t we put that in a browser?
评论 #33815294 未加载
评论 #33815148 未加载
radicalbyteover 2 years ago
So how many of the other CAs work with spyware &#x2F; NSA &#x2F; MI5 etc? Or corporate espionage? I doubt that these are the only bad eggs.
评论 #33814553 未加载
评论 #33814548 未加载
评论 #33814496 未加载
评论 #33814953 未加载