Remix.run Logo
▲ MisterMunchkin 16 hours ago

It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.

▲Tomte an hour ago | parent | next [-]

It is, but that‘s why I trust Honest Achmed (https://bugzilla.mozilla.org/show_bug.cgi?id=647959). He is a man of integrity and will not be bought!

▲evan_a_a 11 hours ago | parent | prev | next [-]

There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.

https://cabforum.org/working-groups/server/baseline-requirem...

▲vg 2 hours ago | parent [-]

CAB has nothing to do with trust/distrust here. Its the Root CA Store Operators (Mozilla, Google, Apple, Microsoft, Adobe) which have to distrust here.

▲vg 2 hours ago | parent | prev | next [-]

Google (GTS) has done the same. GTS controls GlobalSign R4. GlobalSign R4 was a root cert which was created by GlobalSign and later sold to Google.

If a bad actor starts buying up CA's, then very quickly that CA would be distrusted by Root Cert Store Operators. No different than what happened with DigiNotr and Entrust.

▲phillipseamore 13 hours ago | parent | prev [-]

Not a huge difference between buying the root cert itself and getting a cross-sign. LE started out with cross-signs from Identrust.

"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."