It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
Not a huge difference between buying the root cert itself and getting a cross-sign. LE started out with cross-signs from Identrust.
"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.
CAB has nothing to do with trust/distrust here. Its the Root CA Store Operators (Mozilla, Google, Apple, Microsoft, Adobe) which have to distrust here.
In other words: the CAB members would distrust the CA because the CA would be in violation of their individual root store policies, specifically the "you must follow the rules set by the CAB" part.
Google (GTS) has done the same. GTS controls GlobalSign R4. GlobalSign R4 was a root cert which was created by GlobalSign and later sold to Google.
If a bad actor starts buying up CA's, then very quickly that CA would be distrusted by Root Cert Store Operators. No different than what happened with DigiNotr and Entrust.
It is, but that‘s why I trust Honest Achmed (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=647959" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=647959). He is a man of integrity and will not be bought!
MisterMunchkin · · focus · HN ↗
phillipseamore · · focus · HN ↗
"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."
evan_a_a · · focus · HN ↗
<a href="https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.2.5.pdf" rel="nofollow">https://cabforum.org/working-groups/server/baseline-requirem...
vg · · focus · HN ↗
crote · · focus · HN ↗
vg · · focus · HN ↗
If a bad actor starts buying up CA's, then very quickly that CA would be distrusted by Root Cert Store Operators. No different than what happened with DigiNotr and Entrust.
Tomte · · focus · HN ↗