Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Mozilla and Microsoft distrust TrustCor root certificates in their browsers
#1
Exclamation 
Quote:Mozilla and Microsoft have taken action against three root certificates by TrustCor. These root certificates are now distrusted by the browsers.

[Image: trustcor-certificates-firefox.png]

Mozilla set the distrust date to November 30, 2022, while Microsoft sets the date to November 1, 2022. Other browser makers, including Google and Apple may follow.

Concerns about TrustCor were raised on Mozilla's Dev Security discussion forum in early November by Joel Reardon, a professor at the University of Calgary, and others.

The main claim leveled against TrustCor was that it appeared to be tied to Measurement Systems, which "distributed an SDK containing spyware to Android" users. The following evidence was presented:
  • Measurement Systems and TrustCor had their domains registered by Vostrom Holdings.
  • The two entities have identical corporate officers.
  • TrustCor operates the email encryption product MsgSafe. One beta version of MsgSafe contained the "only known unobfuscated version of the spyware SDK" by Measurement Systems.
New information came to light during the course of the discussion on the security group. A representative of TrustCor provided information.

In the end, it was clear that there were ties between Measurement Systems and TrustCor, at least until 2021, and that one developer hired by TrustCor had access to an unobfuscated version of the source code of the Measurement System malware SDK. However, there no evidence of the mis-issuing of certificates was presented.

Mozilla decided to distrust TrustCor certificates from November 30, 2022 that are included in the Mozilla root store. The certificates will be removed from the root store when they expire. The certificates may be removed at an earlier point if "evidence is found that the CA has mis-used certificates or the CA backdates certificates to bypass the distrust-after settings".

Microsoft did not provide a statement to the discussion group, but it set the distrust date to November 1, 2022.

You find the full discussion, evidence and commentary by the TrustCor representative here.
Firefox users may delete TrustCor certificates immediately in the browser.

Note: removing certificates may prevent access to certain sites on the Internet. You may use the "export" feature to save them to the local system, so that you get an option to restore them using the import option.

Here is how that is done:
  1. Load about:preferences#privacy in the web browser's address bar.
  2. Scroll down to the Certificates section.
  3. Activate the "view certificates" button.
  4. Scroll down to TrustCor. The list is sorted alphabetically.
  5. Select each of the TrustCor certificates, then Delete or Distrust, and confirm; this removes the certificates from the browser.
...
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
F-Secure 19.4
What's new in the ...harlan4096 — 09:44
Thunderbird Supernova 115.10.1
Thunderbird Supern...harlan4096 — 09:41
Microsoft Edge 124.0.2478.51
Version 124.0.2478...harlan4096 — 09:40
Rogue Anti-Malware 15.16.1
V15.16.1 04/12/202...harlan4096 — 09:39
Intel Xeon 6 6980P “Granite Rapids-AP” C...
Intel Xeon 6 specs...harlan4096 — 09:37

[-]
Birthdays
Today's Birthdays
avatar (36)RobertUtelt
Upcoming Birthdays
avatar (43)wapedDow
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>