Re: DarkMatter Concerns

2019-03-06 Thread Kathleen Wilson via dev-security-policy
All, Thank you to those of you that have been providing thoughtful and constructive input into this discussion. I have been carefully reading and contemplating all of the messages posted in the mozilla.dev.security.policy forum. As the owner of Mozilla’s CA Certificates Module[1] and in an

Re: Google Trust Services and EJBCA serial number behavior

2019-03-06 Thread Ryan Hurst via dev-security-policy
We have attached two files to the bug (https://bugzilla.mozilla.org/show_bug.cgi?id=1532842), one that provides a list of all certificates issued after ballot 164 that contain 63 bit serial numbers and one that lists all certificates in that set that have not yet been revoked. Ryan Hurst

Re: DarkMatter Concerns

2019-03-06 Thread Ryan Sleevi via dev-security-policy
(Writing in a personal capacity) Benjamin, I've focused only on the substantive new information added to this discussion relevant to trust. I hope the past messages have highlighted why much of the message may be fundamentally misunderstanding the purpose of a root store and the root store

Re: DarkMatter Concerns

2019-03-06 Thread nadim--- via dev-security-policy
On Tuesday, March 5, 2019 at 7:18:39 PM UTC+1, Ryan Sleevi wrote: > On Tue, Mar 5, 2019 at 12:11 PM Matthew Hardeman via dev-security-policy < > dev-security-policy@lists.mozilla.org> wrote: > > By comparison, the discussion around DarkMatter has been more similar to > the discussion of Symantec

RE: DarkMatter Concerns

2019-03-06 Thread Benjamin Gabriel via dev-security-policy
Dear Selena, On Wednesday, 6 March 2019 02:58:19 UTC+4, Selena Deckelmann wrote: > > I think what you've quoted are accurate statements. That is, recent articles > raised questions that I, and others, felt were important to bring to this > public forum to discuss. > While we welcome and are