Google stopped trusting WoSign's SSL certificate and StartCom
This move was made after a GitHub security group informed Google in August 17, 2016 that Chinese Certificte Authority WoSign provided basic authentication for one of GitHub's domains with an unidentified GitHub username. determined without authenticity.
- What is SSL? Is SSL important to the website?
After WoSign was reported, Google conducted a public investigation together with Mozilla and the security community, which discovered some other cases that WoSign also issued incorrect authentication.
As a result, at the end of last year, the technology giant limited the certificates issued by WoSign and StartCom before October 21, 2016, and removed the white list hostname gradually following the releases since Chrome. 56.
Google stopped trusting WoSign's certification and StartCom
In the Google Groups post on Thursday, Chrome security engineer Devon O'Brien said that the company eventually removed the whitelist from Chrome's upcoming release, completely losing confidence in the testimonials. at WoSign and StartCom.
'Since Chrome 61, the white list will be removed, no longer trusting WoSign's current testimonials and (its affiliates) StartCom and all the certificates they have issued,' O'Brien said. . 'Based on Chromium Development Calendar, this change will be visible on Chrome Dev channels in the coming weeks, Chrome Beta will be available from the end of July 2017 and will be released Stable around mid-September 2017.'.
Last year, Apple and Mozilla also stopped trusting the certificates issued by WoSIgn and StartCom on their browsers due to excessive technical and management errors.
'Most importantly, we found they rewritten the date on SSL authentication to pass the time the VA stopped SHA-1 SSL was released on January 1, 2016,' Kathleen Wilson, the Trusted Root Program Manager of Mozilla said. 'In addition, Mozilla also discovered that WoSign took over ownership of another CA named StartCom and did not announce it, according to Mozilla's policy requirements.'
WoSign's authentication issue began in July 2015 and was officially released last year by British Mozilla programmer Gervase Markham on Mozilla's list of security policies.
The reason is due to security mistakes when the company grants authentication
According to Markham, a security researcher accidentally discovered this security mistake when getting a certificate for med.ucf.edu but submitted it to www.ucf.edu and WoSign approved it, turning it into authentication for the main domain of the school. To test, this researcher used this trick for GitHub's base domain (github.com and github.io) by demonstrating sub-domain control. Surprisingly, WoSign then issued a certificate to the entire GitHub main domain.
From September 2017, when accessing websites using WoSign and StartCom HTTPS certificates, a warning will be displayed on the browser. So these sites are advised to replace authentication 'to quickly minimize errors for Chrome users,' O'Brien said.
You should read it
- Protect your GitHub account with two-factor authentication
- How to turn on two-factor authentication to protect your Firefox account
- Why shouldn't SMS be used to authenticate two factors and what are alternatives?
- 5 Multi-Factor Authentication Vulnerabilities and how to fix them
- More than 90% of Gmail users still don't use the two-factor authentication feature
- 5 secure password alternatives you should consider
- Already able to perform two-factor authentication on Instagram without SMS
- How to turn on two-factor authentication on Slack
May be interested
- W3C ignores all criticisms and approves the EME standard for copyright content restrictionsworld wide web consotium (w3c) announced last week about its intention to adopt the encrypted media extensions (eme) as an official standard in the near future.
- Very cool troll Facebook app that helps friends have to wait for your message forevernothing is more boring than having to wait for someone to type very slowly when responding to a message on facebook, staring at the pointer that they are typing and curious what they are writing. this fun entertainment app will help you taste the wait.
- New service Microsoft 365 encapsulates the OS, Office and Microsoft security toolsat the microsoft inspire conference held on july 10, microsoft announced a new service called microsoft 365, which will include three of its earlier separate services, office 365, windows 10 and enterprise mobility + security.
- Host service dark web is hacked, data is stolendeep hosting, a dark web hosting service, has admitted that they have a security problem.
- Experience the timeline feature of Windows 10timeline allows users to view the history of activities on multiple devices, easily working from one device to the other is very convenient. but the truth may not be like a dream.
- Scientists are developing the world's first battery-free phonea group of scientists from the university of washington (uw) has created the world's first phone that doesn't need a battery to operate when it makes an outgoing call and receives an incoming call.