Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

First of all .. are they going to enforce this? Indeed, can they enforce it? Is it possible to detect such certificates and will Mozilla remove root CAs.

Secondly, this doesn't do anything for the fundamental broken design of CAs which is that any CA in the world can issue a certificate for any website. Firefox ships with dozens of certificates for such eminent organizations as "OISTE WISeKey Global Root GA CA" (who they?), basically anyone who can stump up the fee and fill in a form on Mozilla's website. Any of these could issue duplicate or fraudulent certificates, and any of them could be attacked.



It's enforceable because any such fraudulent certificate, once found, identifies both the dodgy intermediate CA and the responsible root CA. The fraudulent cert itself provides all the proof that Mozilla needs to revoke the corresponding root.

The fraudulent certificates could be found and saved by a user using Chrome's certificate pinning feature, or Firefox's Certificate Patrol add-on, or similar.


If one of these certificates are found (and they will be. Just wait), the root will be removed, thus depriving the CA of their business.

At THAT kind of a cost, you'd rather comply I'd say.


It can be enforced, because the certificate chain will indicate that the x.509 cert has been signed by an intermediate CA


Such certificates are allowed in general, just not if the site is a 'global' site (whatever the definition of 'global' would be). That's why I don't think this is enforcible.


Where are you getting this "allowed in general" thing from? I can't see anything in there at all that would imply that.


Many certificates that you can buy today are issued by legitimate resellers of bigger CA's. That's done by the big CA (which is in the list of trusted roots) handing out a CA certificate to the reseller.

We'd probably want to keep this as is or the already way too big list of roots in the browsers becomes totally unmanageable. Or we move back to the days of only a handful of roots, which probably means also going back to the old prices ($500+ a year for a non-ev one)


We're kidding ourselves, totally kidding ourselves, that we have made the CA system "manageable" by allowing CAs to sell subsidiary CAs to other companies. Yes, those certs aren't cluttering up our 2 terabyte hard disks. That's a bad thing, because they're still out there, and they work whether your browser tells you about them or not.


All this means is that CAs have to be a bit more careful who they give reseller certificates to - essentially, only signing reseller certificates for sellers they think are trustworthy.

Because that's what signing a * certificate says - "I trust the owner of this certificate with signing power for every domain". If a particular CA is giving that away to people who shouldn't be trusted with that, then that's pretty shady behaviour on the part of the CA.


They can do public-key pinning like Chrome does (for example, they embed the "mail.google.com" public key into Chrome itself, and verify that it's the certificate you're TLS'ing to.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: