Submission + - Mozilla warns of unknown root certificate authorit ( 1

suraj.sun writes: Mozilla warns of unknown root certificate authority in Firefox

In a startling revelation, the open-source Mozilla project says that its flagship Firefox browser contains a root certificate authority that doesn’t seem to have a known owner.

Here’s the disclosure by Kathleen Wilson, who serves as a peer for the “CA certificates module” within the Mozilla project:

“I have not been able to find the current owner of this root. Both RSA and VeriSign have stated in email that they do not own this root. Therefore, to my knowledge this root has no current owner and no current audit, and should be removed from NSS.” A separate bug report identifies the root certificate authority as “RSA Security 1024 V3.”

Interestingly, that root certificate authority is shown as valid in Apple’s System Roots but not in Microsoft’s.

Mozilla’s own Gervase Markham is worried about the implications:follow Ryan Naraine on twitter

The lack of transparency in 2002 re: the source of added roots means we have no idea whether e.g. some malicious actor slipped an extra one into whatever list they were keeping internally to Netscape, and has been MITMing people ever since.

ZDNet :


