Well, it was on the expected lines. The thread where I highlighted the complicity of CAs was locked by the moderator / someone from Chrome team. It is fantastic to know that all roads seem to lead to Rome. No wonder no one is accountable my friends.
Aaron Gable you quoted CA Browser Forum's regulations from their published document. That section simply covers the baseline requirements. It does not cover what the CA is supposed to do if a breach is found. So you are quoting the wrong section.
The same document outlines Section 220.127.116.11 that clearly states that it is the duty of the CA to revoke the certificate when breach is found.
Section 18.104.22.168 which states that "The CA SHOULD revoke a certificate within 24 hours and MUST revoke a certificate within 5 days if one or more of the following occurs: Under that in point 2: It says - The CA obtains evidence that certificate was misused; .
CAs are not doing that, they do not have the mechanisms in place to revoke the certificates within 5 days. Look at the entire thread, people are simply trying to absolve the CA of any responsibility. That's a very myopic view of how to safeguard and improve safety and security for the consumers on Internet.
Well, the good thing is that we are documenting this entire process now and the next step would be to go to all the sponsors. We understand that this is a marathon but I promise this is just the beginning.
If any of you really care about making Internet safe then you should carefully review the role of basic certificates in enabling online scams. If you are working at Google, then you can evangelise this internally as well.
Google is not Internet. Why should we have to go to two private companies to resolve the issue? Someone has to take a stand, dear friends as I said this is just a beginning. Please don't take this personally.
We are simply curious to know which CAs want to play ball and which ones want to turn a blind eye.
Finally, if CA Browser Forum does not address something properly, we will get that changed too. We are already starting to see a lot of concern from people in the administration.