On Sat, Sep 03, 2016 at 01:33:38PM -0700, Percy wrote:
> Based on the disclosure WoSign/StartCom is trying to bury, WoSign CEO is now 
> also in control of StartCom. Hence, the actively misleading information 
> spread by him should be taken into consideration when talking about StartCom 
> as well.  

Percy,

This really isn't helpful. You've already made your point several
times. Repeating it isn't going to help anybody.

I see no problem with StartCom or WoSign being owned by the same
person. What might be a problem is that they might run some of the
same software. And that if WoSign's software is having issues that
StartCom's software might have the same issues. It would be good
to know what the relationship between the 2 companies is exactly,
to know if we need to have the same concerns for both of them or
not. I understand that at least some of the infrastructure is
shared, but it said nothing about the issuing itself.

If you think there is something wrong with StartSSL, it would be
nice if you can point to specific issues you find with them.

>From the little I understand, I think the frontend might be shared
and that there is a parameter that say to which backend needs to
be connected. And so that the backend might actually run totally
different software for both. At least, that's what I think he
tried to explain, but it wasn't really clear.


Kurt

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to