remove CFCA CA from FF
This bug requests removing the CFCA CA from Firefox, asserting that Firefox 38 “silently injects” an untrustworthy CA from a “totalitarian country,” specifically CFCA. The reporter claims that such CAs can forge arbitrary certificates without being noticed and argues that CFCA should be removed to protect users. A Mozilla participant responded that the request should not be treated as security sensitive and pointed to bug 926029 for an inclusion request, asking for more information about practices that violate Mozilla policies before a CA would be removed. The reporter argued that the obvious nature of the concern was sufficient and referenced past cases involving other CAs. The Mozilla participant stated they suspected no concrete evidence of violations would be forthcoming and marked the bug invalid. The bug is currently resolved as INVALID.
- Bug 1169490 was filed requesting removal of the CFCA root from Firefox.
- Scientia representative — Reported that Firefox 38 injects CFCA and requested its removal, alleging the CA is inherently untrustworthy and can forge arbitrary certificates.
- Bclary representative — Asked for more information about policy-violating practices and referenced bug 926029, leaving the bug open to allow the opportunity to provide details.
- Scientia representative — Argued that no further information beyond the obvious is needed and cited past CA forgery-related cases.
- Bclary representative — Marked the bug INVALID, stating they suspected no concrete evidence of violations would be forthcoming.
- Scientia representative — Made additional remarks about Mozilla and intelligence agencies.