{"id":494,"date":"2014-10-31T12:44:41","date_gmt":"2014-10-31T20:44:41","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=494"},"modified":"2015-06-04T13:08:14","modified_gmt":"2015-06-04T21:08:14","slug":"how-did-i-get-involved-in-pki","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=494","title":{"rendered":"How did I get involved in PKI?"},"content":{"rendered":"<p>In the mid 90s I was a security consultant, I principally worked on authentication systems (Smart cards, One Time Passwords, Kerberos, PKI, etc.).<\/p>\n<p>Back then the only people who cared about these things\u00a0were organizations concerned with protecting lives or money. This meant most of our contracts were with governments, banks, and fortune 50s. This was an amazing experience that I would not trade for the world &#8212; it gave me the chance to work with some amazing\u00a0people in some of the most paranoid and security conscious environments in the world.<\/p>\n<p>While not my first exposure to PKI the first time &#8220;it was all I did&#8221; was when I worked for a company called ValiCert. The founders saw a problem:<\/p>\n<p style=\"padding-left: 30px;\"><em><strong>Who was watching the certificate authorities and who would make sure that the revocation infrastructure would scale to meaningfully work in the event miss-issuances or key compromises happened?<\/strong><\/em><\/p>\n<p>We had developed technologies that were\u00a0intended to address these problems.\u00a0This technology looked very similar to Certificate Transparency, OCSP stapling and certificate pinning which are again all-the-rage these days.<\/p>\n<p>Unfortunately the Certificate Authorities\u00a0did not like the the idea of being &#8220;watched&#8221; by a third-party; the largest CA went so far to threaten with lawsuits and modified\u00a0their Relying Party Agreements to state that third parties could not re-distribute any information about what certificates they had revoked or issued.<\/p>\n<p>Another entity had patents they claimed covered some of our optimizations and given the browsers were minimally investing in this area we did not get adequate traction so\u00a0we\u00a0pivoted into other areas.<\/p>\n<p>For personal reasons I ultimately ended up at Microsoft where I was responsible for a number of security technologies and one of the \u201clittle things\u201d I ran was the Microsoft Root Program.<\/p>\n<p>When this was assigned to me I was told it was the least important thing on my plate and that I could measure my success through the number of\u00a0escalations we got relating to it &#8212; basically I was told to invest as little as possible to keep things quiet. The root program was a necessity but shipping software was what we were all about.<\/p>\n<p>The first thing I did for the root program was review its\u00a0requirements\u00a0and try to understand\u00a0who were its participants and what agreements we had with them. I was surprised to see there were in-essence no requirements, no authoritative list of contacts at each of the organizations and no contracts with any of its members. I felt marginally better when I found that Netscape had only\u00a0one requirement and that was your check for\u00a0$250,000 USD cleared, the upside of which also meant they probably had\u00a0contracts with each CA but there were no technical or audit requirements in their program either.<\/p>\n<p>To remedy I began to work with\u00a0my AWSOME paralegal and lawyer on defining\u00a0the first &#8220;root program&#8221; with both technical and audit requirements. We did not want to approach this as a profit center like Netscape but instead establish a set of requirements that were technically sound that encouraged CAs to spend on improving their infrastructure and having it reviewed by others<\/p>\n<p>To this end I picked up a project that had been begun by my predecessor to work with the American Institute of Public Accountants (AICPA) to help define and adopt what is WebTrust for CAs today.<\/p>\n<p>We were the first root program to adopt this new audit. I remember being interviewed by the AICPA for a video on their website on how excellent it was to work with them \u2013 they must have taken 50 cuts during that session because of my bumbling.<\/p>\n<p>With these new requirements in hand we set out to get contractual agreements with each of the CAs where they would commit to meet these new requirements and make clear conditions on which we could kick them out for not complying. Given this required them to make operational changes to their practices as well as budget and manage a third-party audit\u00a0it took a complete product release cycle to get all of this in place.<\/p>\n<p>At the end of the operating system release we had an audited set of CAs and\u00a0contractual agreements with each one of them. Now our\u00a0goal was to get these CAs into one room so we could encourage them to adopt common issuance practices.<\/p>\n<p>This was important for a number of reasons, one of the most obvious was that each one of the CAs used a different taxonomy to describe what they did. The simplest example of this was that one CAs in-person verified certificate would be called a Class 1 and another&#8217;s\u00a0was a Class 3.<\/p>\n<p>To top things almost all of the CAs wanted to see the browser &#8220;chrome&#8221; differentiate between their weakly authenticated certificates and those that were strongly authenticated. This of course was not possible without a common practices \u00a0and means of marking certificates to make it clear what practices were used in the vetting of the subscriber.<\/p>\n<p>The internal consensus was that there would be value to users to be able to tell the difference\u00a0so we decided to try to make this happen. To do that we arranged to get these CAs\u00a0in one room so we could talk about standardizing practices and certificate formats. \u00a0To make this happen\u00a0I reached out to my contact at the AICPA and asked him to work with me to arrange what was the very first gathering of publicly trusted CAs\u00a0and trust store providers. We met in Washington DC because I felt we could leverage the work done by the\u00a0US Government to accelerate the standardization of these things.<\/p>\n<p>Unfortunately one of the newest CAs who only issued low assurance certificates saw adopting common standards for vetting and labeling a risk to their business and as a result\u00a0they through a\u00a0wrench in the my plan. They filed a claim with the FTC that what the event an attempt to create anti-competitive marketplace\u00a0and as a result\u00a0I was deposed by the DOJ. Ultimately the issue was closed and I understand the disposition was that the claim was baseless.<\/p>\n<p>At this point I was instructed by management and our\u00a0legal council to stop pushing for this standardization as it represented too much legal risk for the company.<\/p>\n<p>As an aside a\u00a0few months later the largest CA acquired the troublemaker.<\/p>\n<p>About a year and a half later the CAs self-organized and attempted to agree on a smaller set of standardization, the definition of what is called Extended Validation today. This was effectively a new label for what most CAs were offering in their &#8220;high assurance&#8221; certificates. The CABFORUM was now born.<\/p>\n<p>At this point I had moved onto another team at Microsoft. During my time at Microsoft I worked on a number of very cool projects with some great people. Several of the projects I worked on used PKI but my involvement was much more on the peripheral to the industry at that point.<\/p>\n<p>Years later I decided to leave Microsoft &#8212; the Diginotar incident was a big contributor to this decision. I felt that the industry was a mess, they were under investing in their infrastructure, not supporting the open source community they were dependent on and not actively working to improve adoption of SSL. I wanted to change this, I had decided I would start my own Certificate Authority and set an example for the industry on how a CA should approach these things.<\/p>\n<p>This is when GlobalSign approached me and asked me to join as their CTO,\u00a0I really liked the team, they were principled, hard working and looking to change the way things were done. I spent nearly three years in this role and we accomplished a great deal, I also still work with them on technical research \/ direction \u00a0but I have since moved onto a startup doing work on Bitcoin related technologies.<\/p>\n<p>I did not accomplish all of the things I wanted to but I still have hopes that these systemic issues will be resolved as I do believe trusted-third parties are needed on the internet.<\/p>\n<p>Anyway this is how I got into PKI.<\/p>\n<p>Ryan<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the mid 90s I was a security consultant, I principally worked on authentication systems (Smart cards, One Time Passwords, Kerberos, PKI, etc.). Back then the only people who cared about these things\u00a0were organizations concerned with protecting lives or money. This meant most of our contracts were with governments, banks, and fortune 50s. This was [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,4],"tags":[146,147,164,25,27,24],"class_list":["post-494","post","type-post","status-publish","format-standard","hentry","category-security","category-thoughts","tag-crt","tag-ct","tag-my-story","tag-ocsp","tag-pki","tag-revocation"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=494"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/494\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}