Chinese CA Issues Certificates To Impersonate Google
Trailrunner7 writes: Google security engineers, investigating fraudulent certificates issued for several of the company's domains, discovered that a Chinese certificate authority was using an intermediate CA, MCS Holdings, that issued the unauthorized Google certificates, and could have issued certificates for virtually any domain. Google's engineers were able to block the fraudulent certificates in the company's Chrome browser by pushing an update to the CRLset, which tracks revoked certificates. The company also alerted other browser vendors to the problem, which was discovered on March 20. Google contacted officials at CNNIC, the Chinese registrar who authorized the intermediate CA, and the officials said that they were working with MCS to issue certificates for domains that it registered. But, instead of simply doing that, and storing the private key for the registrar in a hardware security module, MCS put the key in a proxy device designed to intercept secure traffic.
If we only knew what was really in that "partnership" agreement... Now we do!
When we all agree to the same rules.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
so do we really need them? where did they come from? dark matters for sure;; 1000s of our genuine spiritual & physical allys continue dying daily from 100% preventable starvation, rockets red glare, babys bursting in air etc... still no one is responsible,, or even aware.. momkind new clear options based on the universal spiritual axioms of tears & innocence equaling truth & mercy for all... meanwhile,, good medicine https://www.youtube.com/results?search_query=stem+cell+therapy bad ama https://www.youtube.com/results?search_query=nazi+zion+experiments.. turn it off http://www.youtube.com/results?search_query=WMD+chemtrail+ingredients.. good neighbors http://www.youtube.com/watch?v=nUeNtM6qakk bad "weather' https://www.youtube.com/results? earch_query=wmd+weather+media+censorship... we hang on to our hemispheres as the lights are coming up all over now..... rock on /. https://www.youtube.com/watch?v=H-kA3UtBj4M
Color me shocked
ABC - Anywhere But China.
Or at least their certs removed from valid CA Root lists that, for example, Mozilla uses. If not, why not? A trust has been breached.
...on processing of your private information. It is in its interests to make sure everything is secure until the moment it reaches their servers.
the bottoms butt at my freelance Said. 'Screaming I sse the same sales and so on, Which don't use the To any BSD project, BITTORRENT) SECOND, something that you
Please explain why we offer nearly tariff-free trade with such a prick country? They bleep with US entertainment companies, networking companies, search companies, etc. etc.
Table-ized A.I.
Sooner or later, greed trumps useability. Companies are going to screw one another over in attempts to dominate. We, the users of the internet, lose when these entities play their games on one another, and sooner or later we are going to take to take our marbles and go home -- it's not worth it to play.
I feel we have already reached this state; between the NSA essentially hacking every router as it leaves the factory to China issuing false certs to Google putting their own interests at the top of every search, it seems that the time has come to either consider some international organization to regulate the internet, or abandon TCP/IP and start again with a whole new internet based on something else. Clean sheet.
The way we are currently headed will breed a cesspool of an internet you can't trust for anything -- so why would you use it for shopping, news, banking, or any other activity if you KNOW that every single time you do, you will regret using this medium for anything?
If Amazon, Google, CNN, and heck even Facebook want to stay in business, they need to learn to stop fucking around with their users, because I've essentially had it, and I'm guessing that I cannot be alone in my disdain and distrust of what has become of an internet I used to like.
If telephones are outlawed, then only outlaws will have telephones.
So the "geniuses" at google sent their private key to a company in China and now are surprised to find it was compromised?!
Can't pretty much any high enough level certificate authority issue any damned certificate it wants?
You think America or any other country can't do this stuff? You think they don't?
Sorry, but when every other damned nation is spying and lying, WTF difference is it when China does it? You don't get to pretend it's OK for one country but not another.
Until we start designing stuff which is inherently more secure, and which doesn't have back doors for government .. this is the state of security. You may or may not have it, you have no control over that fact.
America doesn't want people to bypass their spy apparatus any more than China does. Let's not pretend this is any different.
Lost at C:>. Found at C.
Legally, could the US authority be forced to give over a certificate to the US government?
More BS that the chineses are trying to do... What a surprise.
Zscaler does this for every site you visit using https and it's based on California.
My company had massive amounts of fraudulent connection attempts originating from china. We geoblocked china and 95% of it went away. I feel for what the people who live there have to endure but I give ZERO $hits about the negative effects of blocking access to a country that blatantly allows and endorses state sponsored criminal hackers attacking businesses.
I believe in one set of rules for everyone. How do you suppose China would respond if the tables were turned and the governments of GB,France,Germany,USA, Australia, and Canada all set China in their crosshairs and declared open season.
At a _minimum_ MCS's rights need to be revoked. There needs to be an independent audit of any cert that CNNIC has issued _at CNNIC's expense_, and of their operations (both CNNIC, and the organizations to which they've issued certs), or CNNIC should have its rights revoked as well. MCS is completely untrustable, and CNNIC has to prove that they are currently trustable. CNNIC's operations need to be audited or they may just turn around an issue a new cert to MCS. (Or "MCS" with a new name)
Only one solution. Remove them from the cert chain immediately. Do that a few times and then the CAs will start acting as they should.
You have NO IDEA how the world works, and NO CONCEPT of the difference between free and open society, imperfect as they may be, and that of governments of nations like China.
So seriously, fuck off and die.
...to believe that China is the only government doing this.
When a sovereign government or a malicious commercial trusted provider and much up the internet addresses, certificates, keys, or DNS systems, it's time for a white listed internet for regular people.
The dark web is dark for a reason.
JJ
And you expected WHAT-ELSE from China-attached biz-sluts? Chi.com "business" hustlers are Americas obvious and most powerful enemy. RepubliFat and DemoRat ( see Clinton...) pols blojob them all over for pocket-change & campaign cash. Will noone rid of of those pestilent traitors? Chi.com Inc is one huge spy apparatus and deserves to be treated ruthlessly as such. For a more kinder -- gentler approach mebby Obama.natiion can make chi.spy Inc. make them pay for narco.MEX wettbakks or Chicago baby-momaz. You think? Ha ... hahahaha
anyone can revoke certificates, those revoked can be self signed or CA signed. It means you no longer can access that site without a agreeing to some annoying warning dialog. In my software I can easily deny access to anywhere, and push those updates to my users.
What's the real danger is if we start accepting certificates from third parties who cannot be trusted. Remember, CAs are third parties we trust, if we can't trust them then the system falls apart.
"Sorry, but when every other damned nation is spying and lying" - by gstoddart (321705) on Tuesday March 24, 2015 @02:38PM (#49329601) Homepage
See subject & above quote: Makes me ill, but that's what you get with all the "fine fearless leadership" we & other nations have in place (put their by "secret handshake" weasel organization that, for example, MOST our presidents ALL seem have been members of). Guys that join those? Imo, they're whimps that couldn't make it MINUS joining such a group, living a fucking lie (where it's ALL 'setup' for them beforehand, pushing out the RIGHT guys for the job & then putting those dicks in place instead)... yes, folks - that IS how it all really TRULY works!
(... & all it takes is that old saying "1 rotten apple will rot the entire barrel" since 1 does it? Hey, the rest just "join the party"... & for what? Hey, the sociopath's FAVORITE DRUGS: POWER, & CONTROL!)
I mean wtf - what a bunch of BULLSHIT & what makes me say that? Simple - LOOK @ THE RESULTS OF THE JOB THEY DO for shit's sake!
(Seriously... who are ANY of these "politicians" with their bullshit educations (for most of them), & what do they REALLY accomplish, except chaotic lunacy? Are THEY curing AIDS or CANCER?? Hell no! They just breed problems galore!)
I don't *LIKE* bitching but after doing a bit of reading here as well as following 'current events'? I don't like what I see as the results - like ANY employer wouldn't & yes - politicians are our EMPLOYEES, not our masters.
APK
P.S.=> IF our leaders were actually educated people (not taking BULLSHIT like Political Science or Government & Politics for example)?
Well, THEN, We just *might* have a logically & sensibly run planet instead of a nest of power-hungry leeches living off our taxes (& getting retirements for what - a lousy 2-8 yrs. of what they call "work"?) fucking everyone over, including YOU & ME, as well as their own peers + other nations, constantly!
Sometimes, I truly feel I was better off keeping my head in the sand not paying attention to the stupidities I see nowadays since I've started actually listening to the lunacies & madness of their "political world"... apk
DANE/TLSA helps, if browsers actually look for such entries in DNS records.
That's right, they change the authentication cert so that they can pretend to be Google and some others on work computers. This is so they can use their servers as a MITM and sniff https traffic.
When they did that, boy did I complain. But nobody really cared. "It's their computer", "They're required by law!", "You shouldn't be using work computers for that!".
And apparently there are many employers in the western world who do this. It's normal, even a "So what? They're ALLOWED".
But when *China* does it, oh boy is it a different problem then. Then EVERYONE can see why this sort of thing is wrong. Oh yes indeedie.
The problem is we don't like the Chinese government, therefore we LIKE to consider their actions as bad faith, therefore CAN see them as bad faith. We don't see us as them either, so making them out to be bad doesn't reflect badly on us. We DO however like our democracy and companies are, in capitalism, the new church order, therefore attacking OUR governments or OUR companies is reflecting badly on us, because we hope one day to change our government with our actions and give our money to corporations, therefore fund their activities. So when we make them bad, we make our actions bad.
We don't like to think of ourselves as bad people, so the companies we support CANNOT be bad.
But those we don't identify with, we can vilify no problem.
Joe Biden is a square shooter. Joe Biden for 2016!
when the other party isn't smiling and saying Yes while meaning No and backstabbing you with a smile.
Remember when Trustwave did the same thing, but escaped the CA Death Sentence?
http://www.computerworld.com/article/2501291/internet/trustwave-admits-issuing-man-in-the-middle-digital-certificate--mozilla-debates-punishment.html
Why did these guys finally get it, what was the trigger to differentiate between the two events? Will Mozilla follow suit? They still have a bug about the Trustwave CA MITM issue here:
https://bugzilla.mozilla.org/show_bug.cgi?id=724929
Glad to see some responsibility coming down the pipes...