https://blog.mozilla.org/security/2015/03/23/revoking-trust-in-one-cnnic-intermediate-certificate/
CNNIC被发现颁发了用于中间人攻击的证书。该证书被用于部署到网络防火墙中,用于劫持所有处于该防火墙后的HTTPS网络通信,而绕过浏览器警告。
https://blog.mozilla.org/security/2015/03/23/revoking-trust-in-one-cnnic-intermediate-certificate/
CNNIC被发现颁发了用于中间人攻击的证书。该证书被用于部署到网络防火墙中,用于劫持所有处于该防火墙后的HTTPS网络通信,而绕过浏览器警告。
1
wbbim Mar 24, 2015
最后一句是Google发现的
Thanks to Google for reporting this issue to us. http://googleonlinesecurity.blogspot.sg/2015/03/maintaining-digital-certificate-security.html |
2
AstroProfundis Mar 24, 2015
是一张测试用中间证书,虽然我也很想说“终于逮到狐狸尾巴了”不过就看 Mozilla 这篇文章的话感觉 CNNIC 并没有被直接砍死
We believe that this MITM instance was limited to CNNIC’s customer’s internal network. Additional action regarding this CA will be discussed in the mozilla.dev.security.policy forum. |
3
Gandum Mar 24, 2015
该来的还是会来的
|
4
haquasaiku Mar 24, 2015
并没有感到意外
|
5
AstroProfundis Mar 24, 2015 这是 Mozilla 的讨论帖里面的内容,似乎不至于干掉 CNNIC 的证书 ╮(╯-╰)╭
Remember that it is CNNIC's customer who made this mistake. CNNIC, as the CA, is still responsible for it. But I would be surprised if CNNIC themselves have this problem, nonetheless I will ask them. |
6
kaige Mar 24, 2015
这种政权哪些是干不出来的?
|
7
typcn Mar 24, 2015 那些说 CNNIC 不会这么干的,干了之后立马会被吊销的人在哪呢?
让我看见你们的名字 |
8
wdlth Mar 24, 2015
https://support.apple.com/zh-cn/HT204132
Issuer: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA Big Brother is watching you. 不犯二的Chrome好像也是信任的…… |
9
dzxx36gyy Mar 24, 2015
火钳刘明= =,每天都有大事的赶脚,哎
|
10
windyboy Mar 24, 2015
相当喜感
|
11
fashioncj Mar 24, 2015
=、=MITM越来越多了。
|
12
mafuyu Mar 24, 2015
这次的事情没能把CNNIC一刀捅死真是个北上的故事..._(:3」∠)_
|
13
bxgty Mar 24, 2015
对于Mozzilla,最开始添加CA是走流程,现在抓到违规行为考虑对策也是走流程...
CNNIC还是看紧点的好 lol |
14
GhostFlying Mar 24, 2015
这事情觉得最后不会影响到CNNIC,当然可以拉黑了
|
15
youxiachai Mar 24, 2015
CNNIC 这种国家机构,耍起流氓来..挡都档不住..
|
16
cuibty Mar 24, 2015
没憋好屁的CNNIC
|
17
xrui Mar 24, 2015 via Android
我记得以前很多人说CNNIC wosign不会做坏事的
|
18
SuujonH Mar 24, 2015
我想知道的是如果remove了还能下载到这2过浏览器么 XD
|
19
sincway Mar 24, 2015
Chrome 浏览器有自动汇报可疑 Google 域名证书的功能吧... 看那语气
|
20
shippo7 Mar 24, 2015 via iPhone
终于到了这一天
|
21
laoyur Mar 24, 2015
看下面的评论,还有好多中文评论 :)
|
22
pljhonglu Mar 24, 2015
坐等明天上头条~
|
23
meteor Mar 24, 2015
Mozzilla 拼错了...
|
24
Slienc7 Mar 24, 2015 via Android
去ICANN APNIC留言
|
25
eirk2004 Mar 24, 2015
土耳其、巴基斯坦,这些兄弟国家发生这种事可不意外。相比之下,本朝还是有点顾忌的,用的是Google.com自签发假证书
|
28
chengr28 Mar 24, 2015
|