Newsgroups: mozilla.dev.security.policy
From: Paul Wang <1bal...@gmail.com>
Date: Thu, 28 Jan 2010 15:17:11 -0800 (PST)
Local: Thurs, Jan 28 2010 6:17 pm
Subject: Re: CNNIC Root Inclusion
On 1月29日, 上午5时47分, tophits <wan...@gmail.com> wrote:
> After a second thought, I found that even if Firefox didn't add CNNIC Thank you Tophits, for supporting us who are under monitor and > root certificate as built-in object, CNNIC still can issue a false > gmail.com certificate signed by its CNNIC SSL secondary CA certificate > signed by Entrust.net root CA. The browser will still accept the > forged gmail.com certificate without any warning. > So the inclusion of CNNIC Root CA certificate in Firefox is almost > Thus, it is in fact a serious security design flaw in the way that the > 1. Display clear warning message of certificate change, which is > 2. Eye-catching display of certificate signing path for HTTPS > It's a big problem, as you can see the PR China government is actively > It's a real threat to the trust model of PKI. We should have prompt > References: > [1] Certificate Patrolhttp://patrol.psyced.org/https://addons.mozilla.org/en-US/firefox/add... severely limited regarding internet freedom. I maybe risking my personal freedom to discuss with you here. Freedom is the spirit of Opensource anyway, isn't it? If even the SSL fail to protect us, then we can lose the only privacy or freedom we have left. I guess I can still remove CNNIC and Entrust.net from trust list mannually anyway. But disasters could happen to general users who "accidently" said something the government don't like to hear. It's horrible even thinking about it. People's privacy and freedom of speech is all I concerned about. Displaying warning and signing path sounds like a good idea, better than silently nothing. Thank you again. Sincerely, You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||