Apple blocked CNNIC CA months after MITM attacks
In March of this year, Google found unauthorized digital certificates for several Google domains. The root certificate authority for these domains was the China Internet Network Information Center (CNNIC). CNNIC was controlled by the Chinese government through the Ministry of Industry and Information Technology and is now under the management of the Cyberspace Administration of China (CAC). CNNIC was recognized by all major browsers as a trusted Certificate Authority. If CNNIC signs a fake certificate used in a man-in-the-middle attack, no browser will warn of any unusual activity unless the certificate is pinned.
After Google found these unauthorized certificates, both Google and Firefox revoked its trust in CNNIC a few days later, a development we at GreatFire.org have adovacting for since 2013. Apple and Microsoft on the other hand, did not revoke their trust in CNNIC, nor did they make any announcements regarding the security compromise.
In June 2015, Apple quietly published a support article titled “About the security partial trust allow list”. This announcement was made quietly and as far as we can see was not picked up in the media. We did not notice this change until this week. Apple states in the support article that “an intermediate certificate was incorrectly issued by the certificate authority CNNIC. This issue was addressed through the addition of a mechanism to partially trust a CA by trusting only a set of certificates.” This is the same strategy that has been taken by Google and Firefox to block CNNIC.
Apple also published the full domain list signed by CNNIC which might be interesting to researchers.
Microsoft is the only major browser operator left that still trusts CNNIC-issued CAs. Microsoft pointed to a help article when requested for comment. Microsoft didn’t indicate any action against CNNIC in the article. We urge Microsoft to revoke CNNIC following Google, Mozilla and Apple's lead and limit CNNIC's authority to the domain list published by Apple.
评论
When people are more active in the military, they've been by family members and friends. While they will have been fighting across seas, even in distant countries, risking their lives to receive their particular country, a majority of American citizens are enjoying with the serenity that comes out in their sacrifice. We are retained safe from outside threats as a result of novenmber who have served in our country. If not for all these we might well not be living in the independent, first world all of us find ourselves in today. War creates a storyline for publication or movie, but a couple of individuals have experienced to have the pain, and suffering that it may possibly bring upon an individual being. Whether it is nothing but a medic having to a human body that's been mutilated and busted, or soldiers watching a comrade die in conflict, to suffering from injury themselves, novenmber have suffered. gdfghfhjgjkj
you could sign up online for snapchat. Make snapchat online can also snapchatapkdownload See the Snapchat Login Online site.
search to locate something new. So if you are one of those looking. Appvn you might have utilized Appvn for Android by means of apk file and also.
页面
添加新评论