StartCom
   HOME

TheInfoList



OR:

StartCom was a certificate authority founded in
Eilat Eilat ( , ; ; ) is Israel's southernmost city, with a population of , a busy port of Eilat, port and popular resort at the northern tip of the Red Sea, on what is known in Israel as the Gulf of Eilat and in Jordan as the Gulf of Aqaba. The c ...
,
Israel Israel, officially the State of Israel, is a country in West Asia. It Borders of Israel, shares borders with Lebanon to the north, Syria to the north-east, Jordan to the east, Egypt to the south-west, and the Mediterranean Sea to the west. Isr ...
, and later based in
Beijing Beijing, Chinese postal romanization, previously romanized as Peking, is the capital city of China. With more than 22 million residents, it is the world's List of national capitals by population, most populous national capital city as well as ...
,
China China, officially the People's Republic of China (PRC), is a country in East Asia. With population of China, a population exceeding 1.4 billion, it is the list of countries by population (United Nations), second-most populous country after ...
, that had three main activities: StartCom Enterprise Linux (
Linux distribution A Linux distribution, often abbreviated as distro, is an operating system that includes the Linux kernel for its kernel functionality. Although the name does not imply product distribution per se, a distro—if distributed on its own—is oft ...
), StartSSL (
certificate authority In cryptography, a certificate authority or certification authority (CA) is an entity that stores, signs, and issues digital certificates. A digital certificate certifies the ownership of a public key by the named subject of the certificate. Thi ...
) and MediaHost (
web hosting A web hosting service is a type of Internet hosting service that hosts websites for clients, i.e. it offers the facilities required for them to create and maintain a site and makes it accessible on the World Wide Web. Companies providing web ho ...
). StartCom set up branch offices in
China China, officially the People's Republic of China (PRC), is a country in East Asia. With population of China, a population exceeding 1.4 billion, it is the list of countries by population (United Nations), second-most populous country after ...
,
Hong Kong Hong Kong)., Legally Hong Kong, China in international treaties and organizations. is a special administrative region of China. With 7.5 million residents in a territory, Hong Kong is the fourth most densely populated region in the wor ...
, the
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Northwestern Europe, off the coast of European mainland, the continental mainland. It comprises England, Scotlan ...
and
Spain Spain, or the Kingdom of Spain, is a country in Southern Europe, Southern and Western Europe with territories in North Africa. Featuring the Punta de Tarifa, southernmost point of continental Europe, it is the largest country in Southern Eur ...
. Due to multiple faults on the company's end, all StartCom certificates were removed from
Mozilla Mozilla is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, publishes and supports Mozilla products, thereby promoting free software and open standards. The community is supported institution ...
Firefox Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements curr ...
in October 2016 and
Google Chrome Google Chrome is a web browser developed by Google. It was first released in 2008 for Microsoft Windows, built with free software components from Apple WebKit and Mozilla Firefox. Versions were later released for Linux, macOS, iOS, iPadOS, an ...
in March 2017, including certificates previously issued, with similar removals from other browsers expected to follow. StartCom was acquired in secrecy by
WoSign Qihoo 360 (; approximate pronunciation CHEE-hoo), full name 360 Security Technology Inc., is a Chinese internet security company that has developed the antivirus software programs 360 Safeguard and 360 Mobile Safe, the Web browser 360 Secure Brow ...
Limited (
Shenzhen Shenzhen is a prefecture-level city in the province of Guangdong, China. A Special economic zones of China, special economic zone, it is located on the east bank of the Pearl River (China), Pearl River estuary on the central coast of Guangdong ...
,
Guangdong ) means "wide" or "vast", and has been associated with the region since the creation of Guang Prefecture in AD 226. The name "''Guang''" ultimately came from Guangxin ( zh, labels=no, first=t, t= , s=广信), an outpost established in Han dynasty ...
,
China China, officially the People's Republic of China (PRC), is a country in East Asia. With population of China, a population exceeding 1.4 billion, it is the list of countries by population (United Nations), second-most populous country after ...
), through multiple companies,Structure as of October 2016: WoSign CA Limited Hong-Kong → StartCom CA Limited (HK) → StartCom CA Limited (UK) which was revealed by the Mozilla investigation related to the root certificate removal of WoSign and StartCom in 2016. Due to the sanctions of both Mozilla and Apple, the company announced it would be restructured during 2016 by WoSign parent
Qihoo 360 Group Qihoo 360 (; approximate pronunciation CHEE-hoo), full name 360 Security Technology Inc., is a Chinese internet security company that has developed the antivirus software programs 360 Safeguard and 360 Mobile Safe, the Web browser 360 Secure Brow ...
, detaching StartCom from the scandal-affected WoSign and making it a subsidiary of Qihoo.Planned restructure as of October 2016, to be implemented throughout the end of 2016: through the company chain Qihoo 360 → Qifei Int'l Development Ltd. (HK) → StartCom CA Ltd. (HK), which owns 100% of StartCom (CH) and StartCom CA Ltd. (UK), which in turn owns StartCom Ltd. (Israel) and StartCom CA Ltd. (Spain) Despite attempts to distance itself from the controversy, on November 16, 2017, StartCom announced termination of business, and on January 1, 2018, stopped serving new certificates, effectively closing the company. The StartSSL, StartCom, and StartCom CA websites now redirect to WoSign's shop page.


StartSSL

StartCom offered the free Class 1
X.509 In cryptography, X.509 is an International Telecommunication Union (ITU) standard defining the format of public key certificates. X.509 certificates are used in many Internet protocols, including TLS/SSL, which is the basis for HTTPS, the secure ...
SSL certificate "StartSSL Free", which works for webservers (
SSL/TLS Transport Layer Security (TLS) is a cryptographic protocol designed to provide communications security over a computer network, such as the Internet. The protocol is widely used in applications such as email, instant messaging, and voice over IP, b ...
) as well as for E-mail encryption (
S/MIME S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for public-key encryption and signing of MIME data. S/MIME is on an IETF standards track and defined in a number of documents, most importantly . It was originally developed by ...
). It also offered Class 2 and 3 certificates as well as
Extended Validation Certificate An Extended Validation (EV) Certificate is a certificate conforming to X.509 that proves the legal entity of the owner and is signed by a certificate authority key that can issue EV certificates. EV certificates can be used in the same manner as ...
s, where a comprehensive validation (with costs) was mandatory. While certificates were free and unlimited for certain uses, there were limitations imposed unless an upgrade is purchased: * Three-year certificate validity * Certificate revocation requires a fee In June 2011, the company suffered a network breach which resulted in StartCom suspending issuance of digital certificates and related services for several weeks. The attacker was unable to use this to issue certificates (and StartCom was the only breached provider, of six, where the attacker was blocked from doing so).


Trustworthiness

The StartSSL certificate was included by default in
Mozilla Firefox Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements curren ...
2.x and higher, in Apple Mac OS X since version 10.5 (Leopard), all
Microsoft Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
operating systems since 24 September 2009, and
Opera Opera is a form of History of theatre#European theatre, Western theatre in which music is a fundamental component and dramatic roles are taken by Singing, singers. Such a "work" (the literal translation of the Italian word "opera") is typically ...
since 27 July 2010. Since
Google Chrome Google Chrome is a web browser developed by Google. It was first released in 2008 for Microsoft Windows, built with free software components from Apple WebKit and Mozilla Firefox. Versions were later released for Linux, macOS, iOS, iPadOS, an ...
,
Apple Safari Safari is a web browser developed by Apple Inc., Apple. It is built into several of List of Apple operating systems, Apple's operating systems, including macOS, iOS, iPadOS, and visionOS, and uses Apple's open-source software, open-source bro ...
and
Internet Explorer Internet Explorer (formerly Microsoft Internet Explorer and Windows Internet Explorer, commonly abbreviated as IE or MSIE) is a deprecation, retired series of graphical user interface, graphical web browsers developed by Microsoft that were u ...
use the certificate store of the operating system, all major browsers previously included support for StartSSL certificates. On 30 September 2016, during the investigation on
WoSign Qihoo 360 (; approximate pronunciation CHEE-hoo), full name 360 Security Technology Inc., is a Chinese internet security company that has developed the antivirus software programs 360 Safeguard and 360 Mobile Safe, the Web browser 360 Secure Brow ...
, Apple announced that their software will not accept certificates issued by one of the WoSign certificates after 19 September 2016, and said they will take further action on WoSign/StartCom trust anchors as the investigation progresses. On 24 October 2016, Mozilla announced on its security blog that, following its discovery of the purchase of StartCom by another Certificate Authority called WoSign during its investigation on numerous issues with that CA, and that both have failed to disclose this transaction, Mozilla will stop trusting certificates that are issued after 21 October 2016 starting with Firefox 51. On 1 November 2016, Google announced that it too would stop trusting certificates issued after 21 October 2016 starting with Chrome 56. Certificates issued before this date may continue to be trusted, for a time, but in subsequent Chrome releases, these exceptions will be reduced and ultimately removed. On 30 November 2016, Apple products will block certificates from WoSign and StartCom root CAs if the "Not Before" date is on or after 1 Dec 2016 00:00:00 GMT/UTC. As of Version 57, Google Chrome will only trust WoSign/StartCom certificates that were issued to sites in the Alexa Top 1M list, and Chrome 58 will only trust those in the Alexa Top 500k. On 8 August 2017, Microsoft announced on its Windows Security blog that
Windows 10 Windows 10 is a major release of Microsoft's Windows NT operating system. The successor to Windows 8.1, it was Software release cycle#Release to manufacturing (RTM), released to manufacturing on July 15, 2015, and later to retail on July 2 ...
will not trust any new certificates from WoSign and StartCom after September 2017. Despite changes to the company's structure, StartCom did not see "any clear indication from the browsers that StartCom would be able to regain the trust" by the browser companies. Therefore, StartCom has halted the issuing of all certificates since January 1, 2018 and will terminate business completely by 2020 by revoking all issued certificates.


Response to Heartbleed

On 13 April 2014, StartCom announced a
FAQ A frequently asked questions (FAQ) list is often used in articles, websites, email lists, and online forums where common questions tend to recur, for example through posts or queries by new users related to common knowledge gaps. The purpose of a ...
page related to
Heartbleed Heartbleed is a security bug in some outdated versions of the OpenSSL cryptography library, which is a widely used implementation of the Transport Layer Security (TLS) protocol. It was introduced into the software in 2012 and publicly disclos ...
, a critical bug in
OpenSSL OpenSSL is a software library for applications that provide secure communications over computer networks against eavesdropping, and identify the party at the other end. It is widely used by Internet servers, including the majority of HTTPS web ...
estimated to have left 17% of the Internet's secure web servers vulnerable to data theft. StartCom's policy was to charge $25 for each revoked certificate, and it refused to waive this fee in the case of certificates compromised due to Heartbleed, though some paying customers were granted a single free revocation. This caused many to doubt StartCom's status as a certificate authority. When provided with proof of a compromised certificate, StartCom refused to revoke the certificate for free, providing trust even after StartCom had learned that the certificate had been compromised.


Controversies

In August 2016 it was reported that StartCom was sold to WoSign, a Chinese CA. The original disclosure was taken down for legal reasons. However, repostings of the original articles are still available. The relationship is unclear, but it seems as if the StartCom technical infrastructure was being used by WoSign when they were caught issuing about a hundred improperly validated SSL certificates, including a certificate for github.com. An investigation by Google and Mozilla found that WoSign knowingly and intentionally mis-issued certificates in order to circumvent browser restrictions and CA requirements. As a result, Google joined Mozilla and Apple and planned to distrust all WoSign and StartCom certificates beginning in 2017. On July 17, 2017, an announcement was made about the restructuring of the company. It was announced that StartCom is now 100% managed by Qihoo 360, no StartCom employees are working on WoSign premises, audits have been made by external pen testers, and a new CMS system was developed.


See also

*
Cryptography Cryptography, or cryptology (from "hidden, secret"; and ''graphein'', "to write", or ''-logy, -logia'', "study", respectively), is the practice and study of techniques for secure communication in the presence of Adversary (cryptography), ...
*
Public key certificate In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the validity of a Key authentication, public key. The certificate includes the public key and informati ...
*
Public Key Infrastructure A public key infrastructure (PKI) is a set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, store and revoke digital certificates and manage public-key encryption. The purpose of a PKI is to fac ...
*
Let's Encrypt Let's Encrypt is a Non-profit organisation, non-profit certificate authority run by Internet Security Research Group (ISRG) that provides X.509 public key certificate, certificates for Transport Layer Security (TLS) encryption at no charge. It is ...


Footnotes


References


External links

* {{Official website
StartCom blog
Former certificate authorities Israeli companies established in 1999