Stories
Slash Boxes
Comments

SoylentNews is people

posted by on Wednesday April 08 2015, @04:22AM   Printer-friendly
from the about-as-far-as-I-can-throw-you dept.

El Reg has published a story which discusses the steps Google and Mozilla are taking, in response to the apparent misuse of a China Internet Network Information Center (CNNIC) intermediate Cetificate Authority (CA) administered by MCS Holdings, who claim it was all just a big mistake.

Firefox-maker Mozilla has joined Google in refusing to recognize SSL certificates issued by the China Internet Network Information Centre (CNNIC).

This should not be a surprise since:

This comes after a security biz in Egypt used a CNNIC-issued intermediate certificate to create unauthorized SSL certs that could be used to trick people into connecting to bogus, password-stealing Gmail.com or Google.com websites.

As a result:

[A]ll Mozilla products – including the Firefox web browser and the Thunderbird email client, among others – will be updated so that all CNNIC-based certificates issued on or after April 1, 2015 are considered untrusted.

Mozilla said it also plans to ask CNNIC for a comprehensive list of all of its current valid certificates. Any certificates issued before April 1 that are not included on this whitelist will also be subject to potential "further action."

Microsoft has also revoked the suspect CNNIC intermediate CA:

Microsoft is updating the Certificate Trust list (CTL) to remove the trust of the subordinate CA certificate. The trusted root Certificate Authority, the China Internet Network Information Center (CNNIC), has also revoked the certificate of the subordinate CA.

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 4, Informative) by deimios on Wednesday April 08 2015, @05:19AM

    by deimios (201) Subscriber Badge on Wednesday April 08 2015, @05:19AM (#167738) Journal

    Because the world is not black-or-white and Microsoft being a behemoth has many heads. Some of them actually think and some of those actually have good ideas.
    Yes you should take anything coming out of Redmond with a grain of salt and only after 2 service packs, but this time they might be right.

    Starting Score:    1  point
    Moderation   +2  
       Insightful=1, Informative=1, Total=2
    Extra 'Informative' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   4  
  • (Score: 0) by Anonymous Coward on Wednesday April 08 2015, @05:23AM

    by Anonymous Coward on Wednesday April 08 2015, @05:23AM (#167739)

    and only after 2 service packs

    May I have 2 biscuit packs instead? Hell, even to packs of cigarettes would be healthier.

  • (Score: 4, Informative) by FatPhil on Wednesday April 08 2015, @09:59AM

    by FatPhil (863) <reversethis-{if.fdsa} {ta} {tnelyos-cp}> on Wednesday April 08 2015, @09:59AM (#167777) Homepage
    Indeed, and here we have an actual example of /ad hominem/ - that the argument is false because of its source - rather than the "you insulted me, therefore you used /ad hominem/, and therefore you're wrong" bollocks that lots of idiots spout.

    Why should we trust Microsoft? We shouldn't, as they are (tainted by being in part) criminal liars.
    Why should we trust what Microsoft says? We shouldn't, as they are ( - " - ) criminal liars, we should verify it.
    Why should we listen to what Microsoft says? Because how else can we verify or disprove it?

    If AC has some issue with what MS have said in that announcement, perhaps he'd like to document them here. A cursory read of it looks truthful and useful. I expect no response from AC, as he seems a bit of an idiot (which is not an /ad hominem/, it's just an insult - do you see the difference?).
    --
    Great minds discuss ideas; average minds discuss events; small minds discuss people; the smallest discuss themselves
  • (Score: 0) by Anonymous Coward on Wednesday April 08 2015, @04:53PM

    by Anonymous Coward on Wednesday April 08 2015, @04:53PM (#167900)

    Your statement applies even more-so to the NSA, but you'll get mod-bombed to Hell if you even suggest that. All issues are only black-and-white on this site.