Menu
Home Explore People Places Arts History Plants & Animals Science Life & Culture Technology
On this page
StartCom
Company from Israel

StartCom was a certificate authority founded in Eilat, Israel, and later based in Beijing, China, that had three main activities: StartCom Enterprise Linux (Linux distribution), StartSSL (certificate authority) and MediaHost (web hosting). StartCom set up branch offices in China, Hong Kong, the United Kingdom and Spain. Due to multiple faults on the company's end, all StartCom certificates were removed from Mozilla Firefox in October 2016 and Google Chrome in March 2017, including certificates previously issued, with similar removals from other browsers expected to follow.

StartCom was acquired in secrecy by WoSign Limited (Shenzhen, Guangdong, China), through multiple companies, which was revealed by the Mozilla investigation related to the root certificate removal of WoSign and StartCom in 2016. Due to the sanctions of both Mozilla and Apple, the company announced it would be restructured during 2016 by WoSign parent Qihoo 360 Group, detaching StartCom from the scandal-affected WoSign and making it a subsidiary of Qihoo.

Despite attempts to distance itself from the controversy, on November 16, 2017, StartCom announced termination of business, and on January 1, 2018, stopped serving new certificates, effectively closing the company. The StartSSL, StartCom, and StartCom CA websites now redirect to WoSign's shop page.

We don't have any images related to StartCom yet.
We don't have any YouTube videos related to StartCom yet.
We don't have any PDF documents related to StartCom yet.
We don't have any Books related to StartCom yet.
We don't have any archived web articles related to StartCom yet.

StartSSL

StartCom offered the free Class 1 X.509 SSL certificate "StartSSL Free", which works for webservers (SSL/TLS) as well as for E-mail encryption (S/MIME). It also offered Class 2 and 3 certificates as well as Extended Validation Certificates, where a comprehensive validation (with costs) was mandatory.

While certificates were free and unlimited for certain uses, there were limitations imposed unless an upgrade is purchased:

  • Three-year certificate validity
  • Certificate revocation requires a fee

In June 2011, the company suffered a network breach which resulted in StartCom suspending issuance of digital certificates and related services for several weeks.13 The attacker was unable to use this to issue certificates (and StartCom was the only breached provider, of six, where the attacker was blocked from doing so).14

Trustworthiness

The StartSSL certificate was included by default in Mozilla Firefox 2.x and higher, in Apple Mac OS X since version 10.5 (Leopard), all Microsoft operating systems since 24 September 2009,1516 and Opera since 27 July 2010.17 Since Google Chrome, Apple Safari and Internet Explorer use the certificate store of the operating system, all major browsers previously included support for StartSSL certificates.

On 30 September 2016, during the investigation on WoSign, Apple announced that their software will not accept certificates issued by one of the WoSign certificates after 19 September 2016, and said they will take further action on WoSign/StartCom trust anchors as the investigation progresses.18

On 24 October 2016, Mozilla announced on its security blog that, following its discovery of the purchase of StartCom by another Certificate Authority called WoSign during its investigation on numerous issues with that CA, and that both have failed to disclose this transaction,19 Mozilla will stop trusting certificates that are issued after 21 October 2016 starting with Firefox 51.20 On 1 November 2016, Google announced that it too would stop trusting certificates issued after 21 October 2016 starting with Chrome 56. Certificates issued before this date may continue to be trusted, for a time, but in subsequent Chrome releases, these exceptions will be reduced and ultimately removed.21 On 30 November 2016, Apple products will block certificates from WoSign and StartCom root CAs if the "Not Before" date is on or after 1 Dec 2016 00:00:00 GMT/UTC.22

As of Version 57, Google Chrome will only trust WoSign/StartCom certificates that were issued to sites in the Alexa Top 1M list, and Chrome 58 will only trust those in the Alexa Top 500k.23

On 8 August 2017, Microsoft announced on its Windows Security blog that Windows 10 will not trust any new certificates from WoSign and StartCom after September 2017.24

Despite changes to the company's structure, StartCom did not see "any clear indication from the browsers that StartCom would be able to regain the trust" by the browser companies. Therefore, StartCom has halted the issuing of all certificates since January 1, 2018 and will terminate business completely by 2020 by revoking all issued certificates.25

Response to Heartbleed

On 13 April 2014, StartCom announced26 a FAQ page27 related to Heartbleed, a critical bug in OpenSSL estimated to have left 17% of the Internet's secure web servers vulnerable to data theft.

StartCom's policy was to charge $25 for each revoked certificate, and it refused to waive this fee in the case of certificates compromised due to Heartbleed, though some paying customers were granted a single free revocation.282930 This caused many to doubt StartCom's status as a certificate authority.31 When provided with proof of a compromised certificate, StartCom refused to revoke the certificate for free, providing trust even after StartCom had learned that the certificate had been compromised.32

Controversies

In August 2016 it was reported that StartCom was sold to WoSign, a Chinese CA.333435 The original disclosure was taken down for legal reasons.36 However, repostings of the original articles are still available.37 The relationship is unclear, but it seems as if the StartCom technical infrastructure was being used by WoSign when they were caught issuing about a hundred38 improperly validated SSL certificates, including a certificate for github.com.3940

An investigation by Google and Mozilla found that WoSign knowingly and intentionally mis-issued certificates in order to circumvent browser restrictions and CA requirements. As a result, Google joined Mozilla and Apple and planned to distrust all WoSign and StartCom certificates beginning in 2017.41 On July 17, 2017, an announcement was made about the restructuring of the company. It was announced that StartCom is now 100% managed by Qihoo 360, no StartCom employees are working on WoSign premises, audits have been made by external pen testers, and a new CMS system was developed.42

See also

Footnotes

References

  1. "About StartCom". The Register. Apr 26, 2016. Archived from the original on June 25, 2016. Retrieved June 7, 2016. https://web.archive.org/web/20160625001732/https://www.startssl.com/AboutUS

  2. "Distrusting New WoSign and StartCom Certificates". https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/

  3. Adam C. Engst. "Why Take Control Was Briefly Labeled "Not Secure"". Take Control. https://tidbits.com/article/17121

  4. Mozilla (2016-10-10). "WoSign and StartCom". Retrieved 2016-10-25. https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ/edit

  5. Structure as of October 2016: WoSign CA Limited Hong-Kong → StartCom CA Limited (HK) → StartCom CA Limited (UK)

  6. Mozilla (2016-10-10). "WoSign and StartCom". Retrieved 2016-10-25. https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ/edit

  7. apple (2016-09-30). "Blocking Trust for WoSign CA Free SSL Certificate G2 (IOS)". https://support.apple.com/en-us/HT204132

  8. apple (2016-09-30). "Blocking Trust for WoSign CA Free SSL Certificate G2 (MacOS)". https://support.apple.com/en-us/HT202858

  9. Planned restructure as of October 2016, to be implemented throughout the end of 2016: through the company chain Qihoo 360 → Qifei Int'l Development Ltd. (HK) → StartCom CA Ltd. (HK), which owns 100% of StartCom (CH) and StartCom CA Ltd. (UK), which in turn owns StartCom Ltd. (Israel) and StartCom CA Ltd. (Spain)

  10. Qihoo 360 Group (2016-10-14). "StartCom Remediation Plan" (PDF). Archived from the original (PDF) on 2016-10-26. Retrieved 2016-10-25.{{cite web}}: CS1 maint: numeric names: authors list (link) https://web.archive.org/web/20161026080249/https://www.startssl.com/report/StartCom_Remediation_Plan_14102016.pdf

  11. "StartSSL™ Certificates & Public Key Infrastructure". www.startcomca.com. Archived from the original on 2017-12-01. Retrieved 2017-11-17. https://web.archive.org/web/20171201171612/https://www.startcomca.com/index/News/newDetail?date=20171116

  12. 谭晓生 (17 November 2017). "Termination of the certificates business of Startcom". mozilla.dev.security.policy (Mailing list). https://groups.google.com/d/msg/mozilla.dev.security.policy/LM1SpKHJ-oc/4nBsP1xJAQAJ

  13. "Web authentication authority suffers security breach". The Register. June 26, 2011. Retrieved January 14, 2012. https://www.theregister.co.uk/2011/06/21/startssl_security_breach/

  14. "How StartCom Foiled Comodohacker: 4 Lessons". InformationWeek. September 8, 2011. Archived from the original on January 3, 2013. Retrieved December 20, 2012. https://web.archive.org/web/20130103030451/http://www.informationweek.com/security/attacks/how-startcom-foiled-comodohacker-4-lesso/231601037

  15. "Microsoft Adds Support for StartCom Certificates". StartCom.org. September 24, 2009. Archived from the original (Press release) on July 17, 2011. Retrieved 2011-01-14. https://web.archive.org/web/20110717142400/http://www.startcom.org/?app=14&rel=33

  16. "Microsoft updates trusted root certs to include StartCom". Sophos.com Naked Security blog. September 27, 2009. https://www.sophos.com/blogs/chetw/g/2009/09/27/microsoft-updates-root-certs-startcom/

  17. "New Roots, new EV, and a new Public Suffix file". Opera.com Rootstore blog. http://my.opera.com/rootstore/blog/2010/07/28/new-roots-new-ev-and-a-new-public-suffix-file

  18. apple (2016-09-30). "Blocking Trust for WoSign CA Free SSL Certificate G2 (MacOS)". https://support.apple.com/en-us/HT202858

  19. "CA:WoSign Issues - MozillaWiki". Retrieved 2016-10-25. https://wiki.mozilla.org/CA:WoSign_Issues

  20. "Distrusting New WoSign and StartCom Certificates". October 24, 2016. Retrieved 2016-10-25. https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/

  21. "Distrusting WoSign and StartCom Certificates". Google Online Security Blog. Retrieved 2016-11-02. https://security.googleblog.com/2016/10/distrusting-wosign-and-startcom.html

  22. "Lists of available trusted root certificates in iOS". Apple Support Web Site. Retrieved 2016-12-01. https://support.apple.com/en-us/HT204132

  23. "685826 - Restrict the set of domains for WoSign/StartCom certificates - chromium - Monorail". bugs.chromium.org. Retrieved 2017-04-28. https://bugs.chromium.org/p/chromium/issues/detail?id=685826

  24. "Microsoft to remove WoSign and StartCom certificates in Windows 10". Windows Security. Retrieved 2017-08-11. https://blogs.technet.microsoft.com/mmpc/2017/08/08/microsoft-to-remove-wosign-and-startcom-certificates-in-windows-10/

  25. "Termination of StartCom business". www.startcomca.com. Archived from the original on 2017-12-01. Retrieved 2017-12-03. https://web.archive.org/web/20171201171612/https://www.startcomca.com/index/News/newDetail?date=20171116

  26. "Twitter / startssl: We released a small FAQ page ..." StartCom. 13 April 2014. https://twitter.com/startssl/status/455264672892342272

  27. "Heartbleed F.A.Q." StartCom. 13 April 2014. https://www.startssl.com/?app=43

  28. "I use StartCom, and I revoked and re-keyed yesterday. In the revocation reason, ... Hacker News". Geoff. 9 April 2014. https://news.ycombinator.com/item?id=7557845

  29. "Twitter / codeawe: @tonylampada @startssl ..." J. Breitsprecher. 11 April 2014. https://twitter.com/codeawe/status/454504028169584640

  30. "Re: OpenSSL CVE-2014-0160 (aka "Heartbleed")". Jan. 9 April 2014. Archived from the original on 13 April 2014. https://web.archive.org/web/20140413125847/https://forum.startcom.org/viewtopic.php?p=8097

  31. "Most StartSSL certs will stay compromised". 9 April 2014. https://bugzilla.mozilla.org/show_bug.cgi?id=994033

  32. "StartSSL, please revoke me!". 12 April 2014. Archived from the original on April 12, 2014. https://web.archive.org/web/20140412085458/https://revokame.tonylampada.com.br/

  33. "CA:WoSign Issues - MozillaWiki". Retrieved 2016-10-25. https://wiki.mozilla.org/CA:WoSign_Issues

  34. "Thoughts and Observations: WoSign's secret purchase of StartCom; WoSign threatened legal actions over the disclosure". www.percya.com. Archived from the original on 2016-09-05. Retrieved 2016-09-08. https://web.archive.org/web/20160905173058/http://www.percya.com/2016/09/wosigns-secret-purchase-of-startcom.html

  35. "Thoughts and Observations: StartCom operated solely by WoSign in China - an analysis of the new StartCom website". www.percya.com. Archived from the original on 2016-09-07. Retrieved 2016-09-08. https://web.archive.org/web/20160907132911/http://www.percya.com/2016/09/startcom-operated-solely-in-china.html

  36. https://letsphish.org https://letsphish.org?part=about

  37. "Thoughts and Observations: WoSign's secret purchase of StartCom; WoSign threatened legal actions over the disclosure". www.percya.com. Archived from the original on 2016-09-05. Retrieved 2016-09-08. https://web.archive.org/web/20160905173058/http://www.percya.com/2016/09/wosigns-secret-purchase-of-startcom.html

  38. "Incidents involving the CA WoSign". https://groups.google.com/d/topic/mozilla.dev.security.policy/k9PBmyLCi8I/discussion

  39. "CA:WoSign Issues - MozillaWiki". Retrieved 2016-10-25. https://wiki.mozilla.org/CA:WoSign_Issues

  40. "The story of how WoSign gave me an SSL certificate for GitHub.com". https://www.schrauger.com/the-story-of-how-wosign-gave-me-an-ssl-certificate-for-github-com

  41. Seals, Tara (November 2, 2016). "Google to Distrust WoSign/StartCom Certificates". InfoSecurity Magazine. Retrieved July 7, 2017. https://www.infosecurity-magazine.com/news/google-to-distrust-wosignstartcom/

  42. "1311832 - StartCom: Action Items". bugzilla.mozilla.org. Retrieved 2017-08-01. https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c12