Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, Trustico is a reseller. There's very little to stop them doing anything they want, since they are not subject to CABF regulations.

For example, consider this page: https://www.trustico.com.au/ssltools/create/csr-pem/create-a...

The best part - it doesn't even use browser crypto. The private key is generated server-side and then rendered in the server response.

Private key generation on the reseller-side - what can go wrong.



They are still effectively subject to the CA/B rules. The issuer of the certs is subject to the rules, and they must ensure compliance of any companies they delegate to.


Given that they have access to private keys they shouldn't, should Comodo (their new CA partner) then think about stopping them from reselling? Obviously, they've already terminated their relationship with Symantec...


This is not wrong, but in the context of them generating and storing private keys for their users it means there's nothing in the Baseline Requirements preventing them from doing so if the subscriber (user) agrees to it.

However, even if we assume Trustico was an authorized party, the keys became compromised the moment they were disclosed to DigiCert unless the terms their users agreed to included DigiCert as an authorized party. Even if they were you could make an argument that those keys were compromised due to the fact that they were literally sent via email, unless they were properly encrypted and what not.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: