Re: Comodo credibility crisis



Peter Pearson <ppearson@xxxxxxxxxxxxxxx> wrote:

Comodo is a Certificate Authority whose root certificates have the
honor of being in Firefox's built-in certificate set. They seem to
have made The Big Mistake by lending their credibility to a reseller
who signed a cert for Eddy Nigg in the name of mozilla.com:

As far as I can see, the way that commercial certificate authorities
operate is fundamentally broken.

The CAs are paid by those who want to have their keys certified. The
/direct/ benefit for this service is to the reliers, who look at the
certificate and decide whether it's satisfactory evidence that the
public key it quotes really belongs to the entity claimed. The CA makes
money whether the certificate requests are honest or not.

There are second order effects which tend to keep the CAs in line, of
course. A bad CA (one that signs dishonest certificates) loses
reputation and may be withdrawn from the tables built into web browsers
and operating systems; and honest merchants would (presumably) rather be
certified by a good CA than a bad one, since it enhances their
credibility.

But there's still a basic conflict. I wish I knew how to repair this
system, but messing with micropayments to make the CAs more directly
answerable to the reliers doesn't seem sensible. Maybe informal systems
such as PGP's web-of-trust or SPKI/SDSI's everyone's-a-CA approach are
just more resilient.

But to me, the surprise is not that this has happened. It's that it
doesn't happen more often.

-- [mdw]
.



Relevant Pages

  • Re: CERTIFICATE
    ... but the credibility of the server holding ... middle attack with another server housing a certificate. ...
    (Security-Basics)
  • Re: Certificate authorities
    ... CAs are organizations that certify the identity of somebody ... So when you connect to an SSL web site, ... One way to trust a web site is to tell your web browser a list ... those has issued a particular SSL certificate, ...
    (comp.sys.mac.misc)
  • Re: Proposal for a new PKI model (At least I hope its new)
    ... >the certificate they'll sell you probably aren't technical (since the ... Verisign and a hand full of other root CAs are the only globally ... just like how global DNS works. ...
    (sci.crypt)
  • Re: New whitepaper "The Phishing Guide"
    ... a certificate, while they shouldn't. ... Seems like most CAs are more capable of selling certificates than ... that they are trying to protect. ... to protect from unauthorized users, ...
    (Bugtraq)
  • Re: ClickOnce and Certificate
    ... There are some commercial CAs that offer code signing certificates for ... If you're shopping around for alternate CAs, ... > it but $400 for a certificate that takes the company probably no more than ... >> your app inoperational. ...
    (microsoft.public.dotnet.security)

Quantcast