DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 12th November 2022
shep shep is offline
Real Name: Scott
Arp Constable
 
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,517
Default TrustCor Certificate Authority - Not to be trusted

In the culturing an illusion of trust category

From the GrapheneOS Changelog:
Quote:
2022111000

Tags:

TP1A.221005.002.2022111000 (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-10-05 patch level
TP1A.221105.002.2022111000 (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)
TD1A.221105.001.2022111000 (Pixel 7, Pixel 7 Pro)

Changes since the 2022110800 release:

remove TrustCor Certificate Authority due to malicious domain squatting and ties to entites involved in surveillance which should have very little impact on web compatibility due to this CA barely being used by anyone other than a specific dynamic DNS provider
ignore wireless alert channels being marked as always-on to prevent channel configuration overriding presidential alert toggle
GmsCompatConfig: change app label from "GmsCompat config" to "GmsCompatConfig"
GmsCompatConfig: disable TelecomTaskService to resolve sandboxed Google Play services crash caused by feature flag
kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): update base kernel to Android 13 QPR1 Beta 3 to ship the December security update early
Vanadium: update Chromium base to 107.0.5304.105
And the well documented, academic presentation of the evidence:
https://groups.google.com/a/mozilla..../c/oxX69KFvsm4

Last edited by shep; 14th November 2022 at 12:45 PM. Reason: jggimi's spelling correction
Reply With Quote
  #2   (View Single Post)  
Old 14th November 2022
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 8,032
Default

The trailing "e" in the thread title added some confusion for me. The CA's name is "TrustCor" -- no "e".
Reply With Quote
  #3   (View Single Post)  
Old 14th November 2022
shep shep is offline
Real Name: Scott
Arp Constable
 
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,517
Default

I'm unable to correct the spelling in the News list - ?Moderator intervention?

On my current system:

Code:
less /etc/ssl/cert.pem | grep TrustCor
### TrustCor Systems S. de R.L.
=== /C=PA/ST=Panama/L=Panama City/O=TrustCor Systems S. de R.L./OU=TrustCor Certificate Authority/CN=TrustCor ECA-1
        Subject: C=PA, ST=Panama, L=Panama City, O=TrustCor Systems S. de R.L., OU=TrustCor Certificate Authority, CN=TrustCor ECA-1
=== /C=PA/ST=Panama/L=Panama City/O=TrustCor Systems S. de R.L./OU=TrustCor Certificate Authority/CN=TrustCor RootCert CA-1
        Subject: C=PA, ST=Panama, L=Panama City, O=TrustCor Systems S. de R.L., OU=TrustCor Certificate Authority, CN=TrustCor RootCert CA-1
=== /C=PA/ST=Panama/L=Panama City/O=TrustCor Systems S. de R.L./OU=TrustCor Certificate Authority/CN=TrustCor RootCert CA-2
        Subject: C=PA, ST=Panama, L=Panama City, O=TrustCor Systems S. de R.L., OU=TrustCor Certificate Authority, CN=TrustCor RootCert CA-2
Reply With Quote
  #4   (View Single Post)  
Old 14th November 2022
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 8,032
Default

It's already been mentioned on tech@. With the misspelling.

What I know -- just as a user -- is that the OS's certificate list is generally synced with Mozilla, who -- according to the public discussion thread you linked -- have giving this CA until November 22 to address concerns.
Reply With Quote
  #5   (View Single Post)  
Old 14th November 2022
shep shep is offline
Real Name: Scott
Arp Constable
 
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,517
Default

Trade you the "e" in TrustCore for the "ing" in giving.
Reply With Quote
  #6   (View Single Post)  
Old 14th November 2022
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 8,032
Default

Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Google warns of unauthorized TLS certificates trusted by almost all OSes J65nko News 4 25th March 2015 07:11 PM
Launching in 2015: A Certificate Authority to Encrypt the Entire Web J65nko News 1 18th November 2014 11:52 PM
Further evidence of Certificate Authority break-ins J65nko News 0 27th October 2011 08:18 PM
Certification Authority Oko OpenBSD Security 5 18th May 2009 05:16 PM


All times are GMT. The time now is 12:26 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick