Steve Zakulec · @keen456
26 followers · 230 posts · Server infosec.exchange

@SwiftOnSecurity Not sure if you saw this story about getting removed as a root CA, but it's fascinating as a failure in communications, and ultimately trust: groups.google.com/a/mozilla.or TrustCor wasn't accused of anything serious, but they bungled the response so epicly that they might as well have been.

#trustcor

Last updated 2 years ago

Steve Zakulec · @keen456
24 followers · 206 posts · Server infosec.exchange

This is genuinely fascinating watching a company basically destroy a large part of itself, not so much for what they originally did, but how they reacted when asked about it: groups.google.com/a/mozilla.or

#cacert #rootCA #certificates #trustcor

Last updated 2 years ago

Marcel SIneM(S)US ☑️ · @simsus
110 followers · 1240 posts · Server social.tchncs.de
CK's Technology News · @CKsTechNews
1566 followers · 762 posts · Server cktn.todon.de
Filippo Valsorda :go: · @filippo
6031 followers · 67 posts · Server abyssdomain.expert

Chrome will distrust across platforms in Chrome 111 (landing in Stable in March). No grace period for unexpired certificates, unlike Mozilla and Microsoft.

groups.google.com/a/mozilla.or

#trustcor

Last updated 2 years ago

Aegewsh · @m0iga
163 followers · 741 posts · Server 101010.pl

NF.sec – Bezpieczeństwo systemu Linux - Urzędy certyfikacji w systemach Linux mają zbyt prosty pogląd na „zaufanie”
nfsec.pl/security/6460

-certificates

#ca #certificate_authority #certs #distrust #mozilla #policy #ssl #store #tls #trustcor

Last updated 2 years ago

Marcus · @gerowen
320 followers · 2364 posts · Server mastodon.social

and distrust certificates due to suspicions over covert spyware operation

I went ahead and de-registered the TrustCor certificates on all my personal machines. If you're running a Debian system you can do this by running, as root:
dpkg-reconfigure ca-certificates

You'll then be given an option to deselect certain certificates as "trusted".

techspot.com/news/96843-mozill

@hen @techlore @sr @thenewoil

#mozilla #microsoft #trustcor #privacy #security #cybersecurity

Last updated 2 years ago

Marcus · @gerowen
339 followers · 2651 posts · Server mastodon.social

and distrust certificates due to suspicions over covert spyware operation

I went ahead and de-registered the TrustCor certificates on all my personal machines. If you're running a Debian system you can do this by running, as root:
dpkg-reconfigure ca-certificates

You'll then be given an option to deselect certain certificates as "trusted".

techspot.com/news/96843-mozill

@hen @techlore @sr @thenewoil

#mozilla #microsoft #trustcor #privacy #security #cybersecurity

Last updated 2 years ago

Andrew Bennett · @larthallor
17 followers · 130 posts · Server universeodon.com

: cut!

22.04 Patch for
* Add Trustcor root certificates to mozilla/blacklist.txt: (LP: #1998785)
- "TrustCor RootCert CA-1"
- "TrustCor RootCert CA-2"
- "TrustCor ECA-1"

#trustcor #ubuntu #security #mozilla #firefox

Last updated 2 years ago

Jonathan Kamens · @jik
96 followers · 320 posts · Server federate.social

It's obviously good that browsers and other trusted root CA database maintainers are dropping , but it's obviously bad that it got this far. As this article documents, this is just the most recent of many incidents involving suspicious root certificate authorities. We need to get better at this.
washingtonpost.com/technology/

#trustcor #infosec

Last updated 2 years ago

CK's Technology News · @CKsTechNews
1504 followers · 268 posts · Server cktn.todon.de

and moves to distrust the

Background is that TrustCor has dubious military background. If Google will follow will still be debated.

groups.google.com/a/mozilla.or

#mozilla #microsoft #trustcor #ca

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
22604 followers · 642 posts · Server cyberplace.social

Microsoft and Mozilla have dropped . Apple and Google need to follow. washingtonpost.com/technology/

#trustcor

Last updated 2 years ago

Jake Jarvis :unverified: · @jake
76 followers · 105 posts · Server fediverse.jarv.is

@GossiTheDog Holy crap, what a read!

They got absolutely dogpiled on and destroyed by Mozilla, Google, and Apple (rightfully so) and their replies trying to weasel out of defending themselves publicly, and then reluctantly doing so while addressing 75% of their replies to dumb silly “readers” (us?) and the lamestream “media,” and not the people deciding their fate, hurt my brain to read. Just wow.

Did Elon buy a CA without any of us realizing...?

#trustcor #infosec

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
22073 followers · 479 posts · Server cyberplace.social

When the allegations about first surfaced I thought, you know, maybe people are putting two and two together.

However from the thread it’s pretty clear they can’t answer simple questions, and shouldn’t be a trusted root CA. groups.google.com/a/mozilla.or

#trustcor

Last updated 2 years ago

TheBuggers :mastodon: · @thebuggers
56 followers · 1187 posts · Server mastodon.online

Berichte über den Zertifikatsanbieter Systems sorgen für Aufregung. Das Unternehmen, auf dessen Dienste etwa die Browser , und vertrauen, soll Beziehungen zur US-Regierung und zu einem -Hersteller haben. Das könnte die Sicherheit von Webseitenaufrufen massiv gefährden. TrustCor Systems ist durch seine besondere Stellung als -Zertifizierungsstelle auch in der Lage, andere Stellen zur Vergabe von Zertifikaten zu autorisieren.

#root #spyware #firefox #safari #chrome #trustcor

Last updated 2 years ago

· @grumpyoldmarxist
14 followers · 94 posts · Server muenchen.social
Verfassungklage · @Verfassungklage
1253 followers · 50784 posts · Server mastodon.social

des :

könnte Hintertür für - öffnen.

, und vertrauen den von Systems. Laut einem Bericht hat das Unternehmen jedoch Beziehungen zur US-Regierung und zu einem -Hersteller. Das könnte die Sicherheit von Webseitenaufrufen massiv gefährden. ...

netzpolitik.org/2022/sicherhei

#sicherheit #internets #zertifizierungsstelle #us #geheimdienst #chrome #safari #firefox #zertifikaten #trustcor #spyware

Last updated 2 years ago

Verfassungklage · @Verfassungklage
1607 followers · 51598 posts · Server mastodon.social

des :

könnte Hintertür für - öffnen.

, und vertrauen den von Systems. Laut einem Bericht hat das Unternehmen jedoch Beziehungen zur US-Regierung und zu einem -Hersteller. Das könnte die Sicherheit von Webseitenaufrufen massiv gefährden. ...

netzpolitik.org/2022/sicherhei

#sicherheit #internets #zertifizierungsstelle #us #geheimdienst #chrome #safari #firefox #zertifikaten #trustcor #spyware

Last updated 2 years ago

Christian Pietsch 🍑 · @chpietsch
3104 followers · 9016 posts · Server digitalcourage.social

@SibylleBerg

Hier kann man sehen, wie man den -Zertifikaten im Firefox sein Misstrauen aussprechen kann: mastodon.social/@hnapel/109313

#trustcor

Last updated 2 years ago