TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Apple's response to the WoSign incidents

133 点作者 abritishguy超过 8 年前

8 条评论

vtlynch超过 8 年前
Couple notes for people less familiar with the Internet PKI&#x2F;CA industry:<p>1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certificate.<p>2. Now all the root programs (Mozilla, Apple, Microsoft, and Google) need to decide how they will react to this.<p>3. Mozilla proposed dis-trusting all new WoSign&#x2F;StartCom certificates and giving them a chance to re-apply as a trusted CA in a year. This is only their proposed action, and they have not totally committed to it.<p>4. Apple has now said they will take similar action to Mozilla. Apple will block a specific intermediate certificate: &quot;WoSign CA Free SSL Certificate G2&quot;<p>But they will continue to &quot;trust individual existing certificates&quot; if they had been published to Certificate Transparency logs by September 19th.<p>While I have not personally confirmed this, my understanding is that there are other Wosign certificates that are trusted on Apple via cross-signing. So this seems like an incomplete solution - in the sense that some WoSign certificates (mainly the commercial certificates they sell, vs the ones they give away for free) will remain unaffected in anyway.<p>(Someone more familiar with the specifics of the Apple root store may be able to provide more clarity here)<p>5. Google and Microsoft have not yet committed to any action yet. Google will certainly make a detailed public announcement when they are ready.<p>6. Mozilla is meeting with QiHoo (a chinese tech company which owns a majority stake in WoSign). It is expected that Mozilla will make a final decision following this meeting.
评论 #12618871 未加载
评论 #12618384 未加载
评论 #12618668 未加载
评论 #12619277 未加载
TazeTSchnitzel超过 8 年前
Previously on HN, Mozilla&#x27;s response to WoSign (also a good summary of what they&#x27;d done wrong): <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12582534" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12582534</a>
mrweasel超过 8 年前
That should serve as a clear warning to other certificate authorities. Behave or you will be ruined. For most CAs having either Apple, Mozilla, Microsoft or Google remove your root certificate will drive customers away to the point where you might as well close up shop.
评论 #12619230 未加载
l2dy超过 8 年前
I came across this: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT204132" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT204132</a> earlier today.
byuu超过 8 年前
Sorry if this is obvious to others, but just to be clear ...<p>As it&#x27;s widely reported that WoSign has taken over StartCom&#x27;s infrastructure, this implies that StartCom StartSSL Free certificates going forward won&#x27;t be trusted by Apple either, correct?<p>It also sounds a little strange to only call out the free certificates. Are they going to allow new paid OV&#x2F;EV (and what they call &#x27;IV&#x27;) certificates to remain valid?
评论 #12619548 未加载
评论 #12619892 未加载
oneplane超过 8 年前
Seems like a sensible response. I do wonder how they will know what certificates are currently signed by WoSign, as they stated that individual certificates will still be trusted somehow.
评论 #12618164 未加载
评论 #12618154 未加载
fowl2超过 8 年前
Interesting that Apple&#x27;s root program is effectively anonymous– sent from a group alias and signed off as a program.
Animats超过 8 年前
The John Ringo approach, from &quot;Citadel&quot;. A Chinese supplier cut corners on the gold plating of a contact and caused a major accident. The response:<p><i>&quot;The supplier, Qua Tang Electronics, is blacklisted. Find every person associated, every member of the board, every senior officer, and blacklist any company they are associated with as well. With something like this, and the Chinese, there is no overkill. Be wildly unaimed in your fire. Nuke first, ask questions afterward. Make the pain as widespread as possible.&quot;</i>