Comodo credibility crisis



Comodo is a Certificate Authority whose root certificates
have the honor of being in Firefox's built-in certificate
set. They seem to have made The Big Mistake by lending
their credibility to a reseller who signed a cert for
Eddy Nigg in the name of mozilla.com:

(http://groups.google.com/group/mozilla.dev.tech.crypto/browse_thread/thread/9c0cc829204487bf)

Eddy Nigg was alarmed that no sort of checking was done to
verify his authority, and he blew the whistle on them.

Comodo will presumably "fix" this problem by revoking a
few certificates and ostracizing the offending reseller,
but I would argue that a CA's promise that the Bad Thing
will never happen is far more valuable than a promise that
it won't happen *again*.

--
To email me, substitute nowhere->spamcop, invalid->net.
.



Relevant Pages

  • Re: [Full-disclosure] Western Union Certificate Error
    ... Attached is a screenshot of the error and certificate info. SHA-256=9F ... Cert was issued by Comodo ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: Problem Code Signing a VBA Macro in an Excel 2002/2003
    ... Did you try talking to your cert provider, Comodo? ... Perhaps you need to add "Microsoft Enhanced Cryptographic Provider v1.0" as a reference to the project? ... The following doesn't directly answer your question, but suggests a different way to achieve trustedness for your macros (which might be of no interest to you since you've already forked out the dough for a cert). ... > and installed it in my Certificate Store. ...
    (microsoft.public.office.developer.vba)
  • Yet Another CA Reseller hacked...
    ... Es wurde wohl wieder eine COMODO Sub-CA aufgebrochen... ... einfach mal in der im COMODO Root-CA Zertifikat hinterlegten CRL ... |Certificate Revocation List: ...
    (de.comp.security.misc)
  • Re: WHQL and Verisign
    ... > This has nothing to do with trust. ... > the "Root certificate update", I would happily bought one from you. ... I personally trust neither Verisign nor Comodo. ... and you'll find a code signing certificate from ...
    (microsoft.public.development.device.drivers)
  • Re: cant sign assembly - "object already exists" error
    ... i am waiting on comodo to solve this. ... "Sign the assembly" in Visual Studio 2008 in Vista. ... I had other problems using the "Create Test Certificate" button - access ... Delete the private key if the export is successful ...
    (microsoft.public.platformsdk.security)