Re: [websec] Certificate Pinning via HSTS (.txt version)

Gervase Markham <gerv@mozilla.org> Tue, 13 September 2011 20:36 UTC

Return-Path: <gerv@mozilla.org>
X-Original-To: websec@ietfa.amsl.com
Delivered-To: websec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5FDC721F8C88 for <websec@ietfa.amsl.com>; Tue, 13 Sep 2011 13:36:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jmZpCUe0E+hP for <websec@ietfa.amsl.com>; Tue, 13 Sep 2011 13:36:47 -0700 (PDT)
Received: from dm-mail03.mozilla.org (dm-mail03.mozilla.org [63.245.208.213]) by ietfa.amsl.com (Postfix) with ESMTP id 7FB7921F8C85 for <websec@ietf.org>; Tue, 13 Sep 2011 13:36:47 -0700 (PDT)
Received: from [172.16.168.226] (unknown [216.1.177.100]) (Authenticated sender: gerv@mozilla.org) by dm-mail03.mozilla.org (Postfix) with ESMTP id DF98E4AEDAF; Tue, 13 Sep 2011 13:38:53 -0700 (PDT)
Message-ID: <4E6FBF5D.9040509@mozilla.org>
Date: Tue, 13 Sep 2011 13:38:53 -0700
From: Gervase Markham <gerv@mozilla.org>
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:6.0) Gecko/20110808 Thunderbird/6.0
MIME-Version: 1.0
To: Marsh Ray <marsh@extendedsubset.com>
References: <4E6E9B77.1020802@KingsMountain.com> <4E6F9DC6.2080006@stpeter.im> <FA8A58ED-DD2B-446B-9F01-9D1D25140569@checkpoint.com> <4E6FB7CB.3020309@extendedsubset.com>
In-Reply-To: <4E6FB7CB.3020309@extendedsubset.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Cc: IETF WebSec WG <websec@ietf.org>
Subject: Re: [websec] Certificate Pinning via HSTS (.txt version)
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Sep 2011 20:36:48 -0000

On 13/09/11 13:06, Marsh Ray wrote:
> Or not, like the Dutch government, have the pull to convince Mozilla to
> hesitate for a few days to revoke your pwned CA.

That is rather unfair. You make it sound like they asked, and we
complied. In truth, we relied on an assessment of the situation from
GovCERT, the Dutch CERT - who have a decent reputation. When their
assessment changed, we changed our position; whether they should have
made their initial assessment the way they did is a good question, and
one which concerned parties should ask them.

It is certainly not an obvious truth, even more so in the heat of the
moment, that a compromise of one part of a certificate hierarchy at a CA
necessarily means that an entirely different one is also compromised. It
may, it may not - that depends on the arrangement and interlinking or
otherwise of the issuance systems.

Anyway, regardless, the situation is more complex than your allegation
of back-room influence.

Gerv