Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thinking about ad injection, it is actually quite scary what a ISP can do. Not only is it easy to display ads (or possibly even malware), but even worse my ISP is installed as a default CA by Firefox. So that they can even inject into SSL connections, with the only "warning" that the certificate was signed by the ISP...


Who is your ISP, and what CA cert do they have installed?

The thought of an ISP having CA certs that are a part of default installs is unnerving.


Telekom ( actually T-Online, the German ISP branch). The certificate is identified as T-Systems (and I just found another one, Deutsche Telekom AG). Additionally looking through the certificates I found at least Swisscom who appear to have both a CA and an ISP, and AOL. But this is certainly not an exhaustive list but just the ones that caught my eye scrolling through the list of CAs.

[EDIT]And for the added 'told you so,' the German parliament uses precisely this certificate https://www.bundestag.de/


Here's where it was introduced: https://bugzilla.mozilla.org/show_bug.cgi?id=378882

Interesting comment on that thread:

> This CA was singled out as a CA that signed an excessive number of intermediate authorities (252) which together only have issued 4164 certificates in EFFs talk at C3. This is, by far, the highest number, the next contender is GTE Cybertrust with 93.


The bugzilla thread is an interesting read. And to be fair, the issue with the thousands of certificates is explained in it. It appears that the certificate is used to sign DFN, which in turn signs certificates for most German universities.

Btw, Video of the 27C3 talk in question: https://www.youtube.com/watch?v=DRjNV4YMvHI


Wow, reading through that bug makes me glad I never have to deal with Mozilla for anything time sensitive.


Well, you can at least remove those from the trusted cert list manually, but it seems like insanely bad juju for ISPs to have their CAs installed with the browser. I wonder if that's worth opening a bug on the Firefox tracker.


Well, considering Mozilla is who put them in there ...


I always go through and delete government and ISP certs from my computer's cert store.

On OS X, you can do this from Keychain Access.


If you don't need secure access to gov websites this is nice

In my case it was the opposite, a gov website mandated the installation of certificates for its use


That is why you always tell the installer that you do not have a PC or a Mac. Never let them touch your computers.


I'm not quite sure how you got the idea that he let anyone touch his computers out of his post: he said a default CA by Firefox.

There are a number of ISPs that are also CAs that are installed in many browsers by default.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: