News: 1669973451

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Mozilla, Microsoft drop TrustCor as root certificate authority

(2022/12/02)


Mozilla and Microsoft have taken action against a certificate authority accused of having close ties to a US military contractor that allegedly paid software developers to embed data-harvesting malware in mobile apps.

The CA, TrustCor, denies this, but has not responded to direct questions at time of publication.

After a lengthy discussion between staff at Mozilla and Apple, security researchers and the CA itself, Mozilla program manager [1]Kathleen Wilson said the org's concerns were "substantiated" enough to set a distrust date of November 30 for TrustCor's root certificates.

[2]

The back and forth took place on Mozilla's dev-security-policy (MDSP) mailing list, and you can read the full discussion there. Microsoft didn't participate in the conversation; instead, TrustCor executive Rachel McPherson claimed that Microsoft had set a distrust date of November 1 for her company's certs.

[3]

[4]

"Microsoft gave us no advance notice of this decision," McPherson [5]said .

"We have never been accused of, and there is no evidence to suggest that TrustCor violated conduct, policy, or procedure, or wrongfully issued trusted certificates, or worked with others to do so. We have not done any of those things."

[6]

Apple said in its comments that it concurred with the views of other commenters, and that the findings "lend themselves to reasonable doubt about [TrustCor's] ability to operate as a publicly trusted CA."

As of writing, TrustCor's certificates still show up in Apple's list of [7]trusted root certificates , and it's unclear if the iMaker plans to take action of its own.

The anatomy of a trust breakdown

The entire TrustCor affair goes back to [8]early this year , when University of Calgary professor and AppCensus co-founder Joel Reardon discovered data-harvesting malware in a collection of Android apps that had been downloaded more than 46 million times.

The infected apps included a speed camera radar, Muslim prayer apps, QR scanner, weather app and more.

According to Reardon, Panama-based Measurement Systems was the company that developed the code. In the Wall Street Journal's report on Reardon's findings, it claimed it had found ties between Measurement Systems and a Virginia defense contractor doing cyber intelligence, network defense, and intelligence intercept work for the US government.

[9]

The apps were pulled, though some have since returned to Google Play with the offending code removed.

Reardon kicked off [10]another discussion in mozilla.dev.security.policy on November 8, in which he and UC Berkeley's Serge Egelman reported on their digging into Measurement Systems.

Per the pair, Measurement Systems' website was registered by Vostrom Holdings, which does business as Packet Forensics, a company Reardon said sells lawful intercept products to government agencies.

Measurement Systems and TrustCor are both registered in Panama, were registered only a month apart, and have the same set of corporate officers, Reardon said.

The pair also investigated an encrypted email service run by TrustCor called Msgsafe, which they said sends email in plaintext over TLS. Reardon said he's "not convinced there is E2E encryption or that Msgsafe cannot read users' emails."

Reardon emphasized that he had "no evidence that Trustcor has done anything wrong" or "has been anything other than a diligent competent certificate authority."

However, he added: "Were Trustcor simply an email service that misrepresented their claims of E2E encryption and had some connections to lawful intercept defense contractors, I would not raise a concern in this venue. But because it is a root certificate authority on billions of devices – including mine – I feel it is reasonable to have an explanation," Reardon [11]said on the public discussion board.

Unsatisfactory answers

TrustCor's McPherson attempted to answer questions posed by Mozilla and others in the thread, but despite its insistence that Reardon's info was out of date, and that Trustcor and Packet Forensics had no ongoing business relationship, the authorities weren't convinced.

Comments in the discussion thread appeared to be less concerned about the alleged links, and more concerned with the fact that TrustCor couldn't provide satisfactory answers.

"The original concerns, except the potential links to a spyware operation, didn't feel like grounds for distrust to me. However, the way this CA approached the claims leaves me with no trust in their operations," said cryptographer Filippo Valsorda.

Others echoed similar sentiments, saying that McPherson's answers weren't sufficient for a company with [12]as much online power as a Certificate Authority .

"Our assessment is that the concerns about TrustCor have been substantiated and the risks of TrustCor's continued membership in Mozilla's Root Program outweighs the benefits to end users," Mozilla's Wilson said.

We've contacted TrustCor to learn what it plans to do, but haven't yet heard back. ®

Get our [13]Tech Resources



[1] https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y4na0sf7eY9qQSf0EZArDgAAAIE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4na0sf7eY9qQSf0EZArDgAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4na0sf7eY9qQSf0EZArDgAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/WJXUELicBQAJ

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4na0sf7eY9qQSf0EZArDgAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://support.apple.com/en-us/HT212773

[8] https://www.theregister.com/2022/04/11/in_brief_security/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4na0sf7eY9qQSf0EZArDgAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/WJXUELicBQAJ?pli=1

[11] https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ

[12] https://www.theregister.com/2021/11/19/web_trust_certificates/

[13] https://whitepapers.theregister.com/



Rats Abandon a Sinking Ship?

Lil Endian

Oh, lordy! Pessimism radar pegging in the red!

Fair go, Mozilla and Microsoft et al may be acting entirely honestly. I mean, in an infinite universe I can't exclude that! But a few other scenarios refuse to remain quiet in my increasingly Nietzsche-esque mind.

1. They were all in cahoots, but were tipped-off that they were about to be rumbled. Then either TrustCor/Measurement Systems is hung out to dry as the actual perp, or as a patsy.

2. They were all in cahoots, but TrustCor/Measurement Systems narked someone off and "Man Overboard Plan A" was executed.

3. It was a collaboration with TrustCor/Measurement Systems, but the big boys were cut out and so are "doing the right thing". (Who do we know with strong ties to Panama?)

The apps were pulled, though some have since returned to Google Play with the offending code removed.

=> The apps were pulled, though some have since returned to Google Play with the offending code steganographied. (Apologies for uncling my uncle. Tut tut!)

Bill Gates Sends Out Desperate Plea For Help

REDMOND -- In a shocking development, Chief Bloatware Architect Bill Gates
admitted today that Microsoft is in severe financial difficulty and
desperately needs donations to stay afloat through the next month.

"The dismal state of the economy, the lackluster sales of Windows ME, and
the pending anti-trust lawsuit have placed significant financial stress on
Microsoft," Gates said at a press conference. "We can't continue to
develop and maintain our innovative solutions without financial
contributions from users like you."

The company spent the remaining $10,000 in its coffers to send out letters
to registered Windows users pleading for donations.

"For just pennies a day, you can help support the world's most innovative
company in its quest to discover the cure for the Blue Screen of Death,"
the letter announces. "Or you can help fund research and development into
improving the security of our products against such sinister forces as
script kiddies, crackers, and Linux freaks."