Newsgroups: mozilla.dev.security.policy
From: LionheartZhang <flying19880...@gmail.com>
Date: Thu, 28 Jan 2010 22:04:06 -0800 (PST)
Local: Fri, Jan 29 2010 1:04 am
Subject: Re: CNNIC Root Inclusion
On Jan 29, 5:47 am, tophits <wan...@gmail.com> wrote:
> After a second thought, I found that even if Firefox didn't add CNNIC +1,Should use a more compelling way to prompt the user to change any > root certificate as built-in object, CNNIC still can issue a false > gmail.com certificate signed by its CNNIC SSL secondary CA certificate > signed by Entrust.net root CA. The browser will still accept the > forged gmail.com certificate without any warning. > So the inclusion of CNNIC Root CA certificate in Firefox is almost > Thus, it is in fact a serious security design flaw in the way that the > 1. Display clear warning message of certificate change, which is > 2. Eye-catching display of certificate signing path for HTTPS > It's a big problem, as you can see the PR China government is actively > It's a real threat to the trust model of PKI. We should have prompt > References: > [1] Certificate Patrolhttp://patrol.psyced.org/https://addons.mozilla.org/en-US/firefox/add... of the relevant certificate CNNIC is a puppet for the PRC Government to provide all facilities, we do not believe CNNIC. I have canceled CNNIC ROOT and the related certificate of trust option, but not everyone know how to do it. Since the issuance of certificates for the CNNIC, I have canceled the trust of Entrust, I would rather give up their certificates and use Entrust on any website, I do not want this list continues to grow. I'm just an ordinary Chinese netizens, the main purpose is to obtain information and knowledge, but the PRC Government do everything possible to intercept them. The SSL certificate is used to attack no one will be surprised, there is a certain web-based Chinese netizens think that this is a matter of course will be happen. You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||