Mozilla, Microsoft drop root Certificate Authority • The Register
Mozilla, Microsoft drop root Certificate Authority • The Register
Updated Mozilla and Microsoft have taken action against a certificate authority accused of having close ties to a US military contractor that allegedly paid software developers to embed data-harvesting malware in mobile apps.
The CA, TrustCor, denies this, but has not responded to direct questions at time of publication.
After a lengthy discussion between staff at Mozilla and Apple, security researchers and the CA itself, Mozilla program manager Kathleen Wilson said the org's concerns were "substantiated" enough to set a distrust date of November 30 for TrustCor's root certificates.?
The back and forth took place on Mozilla's dev-security-policy (MDSP) mailing list, and you can read the full discussion there. Microsoft didn't participate in the conversation; instead, TrustCor executive Rachel McPherson claimed that Microsoft had set a distrust date of November 1 for her company's certs.?