Newsgroups: mozilla.dev.security.policy
From: Nelson Bolyard <NOnelsonS...@NObolyardSPAM.me>
Date: Wed, 27 Jan 2010 09:11:29 -0800
Local: Wed, Jan 27 2010 12:11 pm
Subject: Re: CNNIC Root Inclusion
On 2010-01-27 06:18 PST, Eddy Nigg wrote:
> On 01/27/2010 04:14 PM, Eddy Nigg: It is? >> I was made aware of some controversial issues regarding the inclusion >> of the CNNIC Root. Please see comments >> https://bugzilla.mozilla.org/show_bug.cgi?id=476766#c18 and the item >> thereafter. >> Even though this is mostly a technical forum, I've seen MANY rants in past years from people who got infected by signed I've also seen a lot of confusion in the past over who is the source if Now, we come to the immediate cases to which Eddy provided links: > http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client... I cannot determine, from the information presented on those pages, if CNNIC > http://www.siteadvisor.com/sites/cnnic.net.cn > http://en.wikipedia.org/wiki/China_Internet_Network_Information_Cente... was itself the source (the signer) of the signed software, or was merely the issuer of certificates that were used by other subjects to sign malware. The middle of those 3 links says that CNNIC had links to another site, tech.sina.com.cn, which on its face seems to be another organization. This doesn't seem inconsistent with CNNIC's role as a CA. I think we need to be very careful to avoid getting caught in the trap of You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||