Skip to content

Why do you trust CNNIC? #15073

Description

@buckle2000
  • Subsystem: tls
  • CNNIC has made tons of malware
  • CNNIC has issued cert for possible MiTM attempt (distrust from Mozilla & Google)
  • CNNIC has once banned personal registration for it's own profit (& political power)
  • CNNIC has recalled several registered .cn domains arbitrarily for no prior acknowledgement from domains' owners (because domain name is same as names of Chinese athletes in 2008 Olympics)

You really shouldn't trust CNNIC.

Activity

  1. jasnell commented on Aug 29, 2017

    @jasnell
    Member

    I want to clarify: this is in relation to including cnnic is the default trusted certs? Correct?

  2. refack commented on Aug 29, 2017

    @refack
    Contributor

    Hello @buckle2000,
    The current procedure for root CA trust is to mirror the list provided by Network Security Services (NSS).
    Feel free to raise a PR to update that list, or the version that's embedded in node (similar to #13279).

  3. added
    cryptoIssues and PRs related to the crypto subsystem.
    securityIssues and PRs related to security.
    questionIssues asking questions about Node.js.
    on Aug 29, 2017
  4. TimothyGu commented on Aug 29, 2017

    @TimothyGu
    Member

    Hi! We take TLS security seriously. We follow recommendations set up by major browser vendors (Mozilla, Google, and others) with regards to CA. In fact, we have already distrusted all new CNNIC-issued certificates in accordance with Mozilla since #1895 (landed two years ago), which is in the latest release of all support release branches.

    If you believe the a supported version of Node.js does not distrust some CNNIC-issued certificates when it should, please email security@nodejs.org as documented in https://github.com/nodejs/node/blob/master/README.md

    /cc @shigeki

    Edit: Fix truncated response.

  5. shigeki commented on Aug 29, 2017

    @shigeki
    Contributor

    Yes, the CNNIC root certs is now included but the certificates issued by CNNIC are filtered with the whitelist of https://github.com/nodejs/node/blob/master/src/CNNICHashWhitelist.inc which is provided by Mozilla.

    Recently, the CNNIC root cert was removed in Mozilla's root certs list in https://bugzilla.mozilla.org/show_bug.cgi?id=1356623 and we are waiting for Firefox56 to be stable.
    After releasing Firefox56, we are going to update root certs so that all certs issued by CNNIC will be distrusted.

  6. shigeki commented on Aug 29, 2017

    @shigeki
    Contributor

    Closing as I described above.

  7. buckle2000 commented on Oct 7, 2017

    @buckle2000
    Author
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.questionIssues asking questions about Node.js.securityIssues and PRs related to security.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions