Chinese CA Issues Certificates To Impersonate Google
Trailrunner7 writes: Google security engineers, investigating fraudulent certificates issued for several of the company's domains, discovered that a Chinese certificate authority was using an intermediate CA, MCS Holdings, that issued the unauthorized Google certificates, and could have issued certificates for virtually any domain. Google's engineers were able to block the fraudulent certificates in the company's Chrome browser by pushing an update to the CRLset, which tracks revoked certificates. The company also alerted other browser vendors to the problem, which was discovered on March 20. Google contacted officials at CNNIC, the Chinese registrar who authorized the intermediate CA, and the officials said that they were working with MCS to issue certificates for domains that it registered. But, instead of simply doing that, and storing the private key for the registrar in a hardware security module, MCS put the key in a proxy device designed to intercept secure traffic.
When we all agree to the same rules.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Or at least their certs removed from valid CA Root lists that, for example, Mozilla uses. If not, why not? A trust has been breached.
...on processing of your private information. It is in its interests to make sure everything is secure until the moment it reaches their servers.
And if you live there, China wants a monopoly on knowing your private information...plus incarcerating you and even killing you to harvest your transplantable organs should it find that it doesn't like something it learns about you. Like that you think Tibet should be free. Or if you worship the wrong god.
Please do try to keep a sense of perspective?
For your security, this post has been encrypted with ROT-13, twice.
Please explain why we offer nearly tariff-free trade with such a prick country? They bleep with US entertainment companies, networking companies, search companies, etc. etc.
Table-ized A.I.
Sooner or later, greed trumps useability. Companies are going to screw one another over in attempts to dominate. We, the users of the internet, lose when these entities play their games on one another, and sooner or later we are going to take to take our marbles and go home -- it's not worth it to play.
I feel we have already reached this state; between the NSA essentially hacking every router as it leaves the factory to China issuing false certs to Google putting their own interests at the top of every search, it seems that the time has come to either consider some international organization to regulate the internet, or abandon TCP/IP and start again with a whole new internet based on something else. Clean sheet.
The way we are currently headed will breed a cesspool of an internet you can't trust for anything -- so why would you use it for shopping, news, banking, or any other activity if you KNOW that every single time you do, you will regret using this medium for anything?
If Amazon, Google, CNN, and heck even Facebook want to stay in business, they need to learn to stop fucking around with their users, because I've essentially had it, and I'm guessing that I cannot be alone in my disdain and distrust of what has become of an internet I used to like.
If telephones are outlawed, then only outlaws will have telephones.
Can't pretty much any high enough level certificate authority issue any damned certificate it wants?
You think America or any other country can't do this stuff? You think they don't?
Sorry, but when every other damned nation is spying and lying, WTF difference is it when China does it? You don't get to pretend it's OK for one country but not another.
Until we start designing stuff which is inherently more secure, and which doesn't have back doors for government .. this is the state of security. You may or may not have it, you have no control over that fact.
America doesn't want people to bypass their spy apparatus any more than China does. Let's not pretend this is any different.
Lost at C:>. Found at C.
My company had massive amounts of fraudulent connection attempts originating from china. We geoblocked china and 95% of it went away. I feel for what the people who live there have to endure but I give ZERO $hits about the negative effects of blocking access to a country that blatantly allows and endorses state sponsored criminal hackers attacking businesses.
I believe in one set of rules for everyone. How do you suppose China would respond if the tables were turned and the governments of GB,France,Germany,USA, Australia, and Canada all set China in their crosshairs and declared open season.
At a _minimum_ MCS's rights need to be revoked. There needs to be an independent audit of any cert that CNNIC has issued _at CNNIC's expense_, and of their operations (both CNNIC, and the organizations to which they've issued certs), or CNNIC should have its rights revoked as well. MCS is completely untrustable, and CNNIC has to prove that they are currently trustable. CNNIC's operations need to be audited or they may just turn around an issue a new cert to MCS. (Or "MCS" with a new name)
The issue isn't about Google giving them their key or anything. CNNIC is a root level CA and is considered trusted by all the major operating systems. CNNIC gave their keys to MCS temporarily and MCS used that authority to issue certs with falsified info.
Nothing wrong in pointing out that an advertising company whose sole business is spying on their users would make sure that any competition is eliminated.
It is possible to dislike both. Please do try to use your brain.
There is when it's totally off-topic and entirely irrelevant. It doesn't matter that Google is involved; this is about China and spying on their own citizens. Google's business model has nothing to do with it. Disliking Google has even less to do with it...because Google is, to date, the only tech company that has ever stood up to China over things like this. In this situation Google is actually the good guys.
And, for the record, every company wants a monopoly. That's why monopolies were outlawed. I think it's you that should use your brain.
For your security, this post has been encrypted with ROT-13, twice.
Google is completely OK with sharing personal info with all governments
Not true, not in the slightest. Google has fought hard to minimize the information they have to give to governments, and to be as transparent as the law will allow about what they do give. Remember that Google created the transparency report, and was the company that managed to negotiate permission to share aggregated data about National Security Letters. Many other companies have followed suit, but Google led the way.
They have already been caught supplying users' data to the US government.
No, Google has been shown to comply with legal requirements, and to fight questionable requests in court. Snowden also revealed that the NSA was tapping Google's fiber. Google responded by encrypting the data on that fiber.
They make money on that as well because they charge the US government a fee for that service.
Cite? Since Google is a publicly-traded company, it should be easy to point to that line item in their SEC filings.
Stood up and achieved what? Get told by the Chinese government to STFU or GTFO?
No, told by the Chinese government to participate in government-mandated censorship or GFTO. Google participated for a while and then decided it wasn't what they ought to be doing, and so chose to GTFO of the biggest market on the planet (albeit one in which they had a small market share.
Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.