Re: Misissuance Report: Incorrect CA-Issuers URI in some certificates

2019-07-23 Thread Wayne Thayer via dev-security-policy
Neil, Thank you for posting this detailed incident report. I have created https://bugzilla.mozilla.org/show_bug.cgi?id=1568356 to track this issue and I have no questions at this time. - Wayne On Tue, Jul 23, 2019 at 10:20 AM Neil Dunbar via dev-security-policy <

Re: Nation State MITM CA's ?

2019-07-23 Thread nyxtom--- via dev-security-policy
On Wednesday, January 6, 2016 at 5:08:10 PM UTC-6, Paul Wouters wrote: > As was in the news before, Kazakhstan has issued a national MITM > Certificate Agency. > > Is there a policy on what to do with these? While they are not trusted, > would it be useful to explicitely blacklist these, as to

DarkMatter CAs in Google Chrome and Android

2019-07-23 Thread Devon O'Brien via dev-security-policy
(Writing on behalf of Google Chrome and Android) On behalf of Google Chrome and Android, we would like to thank the participants that have contributed to the discussion on the broader M.D.S.P thread on this topic. We will be taking similar steps to those proposed by Wayne and approved by

Misissuance Report: Incorrect CA-Issuers URI in some certificates

2019-07-23 Thread Neil Dunbar via dev-security-policy
To m.d.s.p, The following contains an incident report, compiled as a result of the release of two example certificates with an incorrect CA-Issuers URI included. Any questions or observations on this incident are gratefully received, and I will endeavour to answer them as quickly as I can.

Re: Nation State MITM CA's ?

2019-07-23 Thread whateverusernameforme--- via dev-security-policy
On Tuesday, July 23, 2019 at 7:34:11 AM UTC+4, Matthew Hardeman wrote: > It is an interesting question. It essentially becomes a gamble on whether > they'll back down or just fork their own KazakhFox. But if they do push > this all the way with a national browser, then their people are even >