GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Andrew Ayer (agwa@follow.agwa.name)'s status on Sunday, 01-Dec-2024 03:19:29 JST Andrew Ayer Andrew Ayer
    A Brazilian certificate authority trusted only by Microsoft has issued a presumably-unauthorized certificate for google.com: https://bugzilla.mozilla.org/show_bug.cgi?id=1934361

    This can used to intercept traffic to Google from Edge and other Windows applications (except Chrome and Firefox). Hug-ops to Google folks.

    Microsoft are well aware of the extensive history of problems with this CA - I emailed them my concerns in 2021, and further issues were raised during a public CCADB discussion in 2022 - but they clearly don't care. I hope this incident prompts some change; Windows users deserve better!
    In conversation about 6 months ago from follow.agwa.name permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      1934361 - ICP-Brasil: Mis-issued certificate
      UNCONFIRMED (nobody) in CA Program - CA Certificate Compliance. Last updated 2024-11-30.
    • Embed this notice
      waldi (waldi@chaos.social)'s status on Sunday, 01-Dec-2024 19:35:55 JST waldi waldi
      in reply to
      • bkim

      @bkim @agwa google.com sets a CAA record that explicitely forbids issuance by anyone except Google's own CA. A public trusted WebPKI CA is required to check this.

      In the end it just adds to the list of problems that where already mentioned in the two unsuccessful inclusion requests to Mozilla. And it seems Microsoft does not care.

      In conversation about 6 months ago permalink

      Attachments


      1. No result found on File_thumbnail lookup.
        this.in - このウェブサイトは販売用です! - This リソースおよび情報
        このウェブサイトは販売用です! this.in は、あなたがお探しの情報の全ての最新かつ最適なソースです。一般トピックからここから検索できる内容は、this.inが全てとなります。あなたがお探しの内容が見つかることを願っています!
    • Embed this notice
      bkim (bkim@mastodon.social)'s status on Sunday, 01-Dec-2024 19:35:56 JST bkim bkim
      in reply to

      @agwa I'm curious about the discussions on this CA, what are the issues? It is the root for several Brazilian government services, and I had the (layman's) impression that they are competent.

      In conversation about 6 months ago permalink
      Rich Felker repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.