Block leaked FreeBrowser root cert with OneCRL
Categories
(Core :: Security Block-lists, Allow-lists, and other State, task)
Tracking
()
People
(Reporter: dveditz, Unassigned)
Details
(Keywords: sec-other, Whiteboard: [ca-onecrl])
Folks from GreatFire.org who make the Freebrowser wrote our security reporting address to inform us that their product had installed a root certificate on their customer's systems, but with the private key embedded in the executable and easily retrieved. Although this shipped to a relatively small number of users, and they will attempt to remove the root in an update to their product, they are asking browser vendors to distrust this cert and any certs it signs. Since their product is intended to circumvent censorship firewalls, there could be high interest in abusing this certificate against our shared users, and their product updates might be blocked.
Excerpted from their report:
Incident Details
Software: FreeBrowser https://freebrowser.org/
Affected Versions: 6.0.6
Estimated Affected Users: 5,000
Discovery Date: 03/01/2025
Certificate Details
Subject: C=AU, ST=Some-State, O=Internet Widgits Pty Ltd
Issuer: C=AU, ST=Some-State, O=Internet Widgits Pty Ltd (self-signed)
Serial Number: 431ABDBCA032805D37A415D18E8A82D1ABD9EC30
SHA-256 Fingerprint: 90:0E:00:20:A5:0D:70:E8:07:B7:15:85:61:71:74:C6:16:1F:5D:F5:10:10:CD:83:F5:7E:F8:AD:83:13:C7:E7
SHA-1 Fingerprint: FE:F1:64:AD:9C:CB:01:14:B8:3C:00:86:EC:76:DE:F2:65:61:0D:99
Not Before: 2024-06-03 14:07:29 GMT
Not After: 2051-10-19 14:07:29 GMT
Public Key Algorithm: EC (Elliptic Curve)
Signature Algorithm: ecdsa-with-SHA256
Basic Constraints: CA:TRUE (Certificate Authority)
The certificate was installed as a trusted root CA via:
Windows: Added to LocalMachine\Root store via PowerShell
macOS: Added to System keychain with trustRoot flag via security command
Linux: Overwrote user's NSS database (~/.pki/nssdb)
Remediation Actions Taken
Immediate: Stopped distribution of affected software versions
Emergency Update: Next version of software deletes certificate from system stores
Remediation Actions Requested
Detection: Add certificate fingerprint to Chrome's malicious certificate detection
Monitoring: Watch Certificate Transparency logs for certificates signed by this key
User Warnings: Display security warnings when encountering certificates signed by this root
Telemetry: Help assess scope of affected users if possible
Please find the complete certificate below:
-----BEGIN CERTIFICATE-----
MIIB4DCCAYegAwIBAgIUQxq9vGAygF03pBXRjoqC0avZ7DAwCgYIKoZIzj0EAwIw
RTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoMGElu
dGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAgFw0yNDA2MDMxNDA3MjlaGA8yMDUxMTAx
OTE0MDcyOVowRTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAf
BgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDBZMBMGByqGSM49AgEGCCqG
SM49AwEHA0IABFWeUd4ZrxQ8BJG/G+Be3TCNxCqWz3IJlcvvsLW14OVRVA1afuwE
y+/WogrzmlSTc50vGGvT4zzQfNUVUju/NX6jUzBRMB0GA1UdDgQWBBTn4XETMmYe
c2h0rCkGRuBTk4t/gjAfBgNVHSMEGDAWgBTn4XETMmYec2h0rCkGRuBTk4t/gjAP
BgNVHRMBAf8EBTADAQH/MAoGCCqGSM49BAMCA0cAMEQCIFKVXsgByu3qhPbl6ik4
gVvEBqqgwzox1dSuRP5a9qmjAiBdnJkgKgzJa7dLkgpyTIUdBnHle1o82e4c5EwT
oOIIFg==
-----END CERTIFICATE-----
| Reporter | ||
Comment 1•1 year ago
|
||
The "Affected Versions" says 6.0.6 (only) but the certificate and key are still embedded in the current 6.2.0 downloads
| Reporter | ||
Comment 2•1 year ago
|
||
Sheldon from GreatFire said their cert is now in Chrome's CRLSets and that they'd appreciate us adding it to our OneCRL when I asked if that's what they wanted us to do.
The cert may still be in their software, to be used when running their browser, but only version 6.0.6 installed it into the system store where it potentially put other browsers at risk.
Comment 3•1 year ago
|
||
Ben, I've added the following entry to onecrl staging:
{
"subject": "MEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQ=",
"pubKeyHash": "RGObk+I5lXFq77dZEeDHMb4KmhyXECijs4uez6wlLyM=",
"enabled": true,
"details": {
"who": "",
"created": "",
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1976286",
"name": "",
"why": ""
}
}
Can you confirm it looks good and approve it?
Comment 4•1 year ago
|
||
This looks good. I'll log in and approve it.
Comment 5•1 year ago
|
||
% python compare.py
[12:51:45] Stage-Stage: 1696 Stage-Preview: 1696 Stage-Published: 1696 compare.py:67
[12:51:46] Prod-Stage: 1696 Prod-Preview: 1696 Prod-Published: 1695 compare.py:75
Verifying stage against preview compare.py:82
prod/security-state-staging (1696) and prod/security-state-preview (1696) are equivalent compare.py:87
prod/security-state-staging (1696) and prod/security-state-staging (1696) are equivalent compare.py:87
[12:51:47] prod/security-state-staging (1696) and prod/security-state-preview (1696) are equivalent compare.py:87
prod/security-state-preview (1696) and prod/security-state-staging (1696) are equivalent compare.py:87
prod/security-state-preview (1696) and prod/security-state-preview (1696) are equivalent compare.py:87
prod/security-state-staging (1696) and prod/security-state-preview (1696) are equivalent compare.py:87
No changes are waiting in staging compare.py:90
There are 1 changes waiting in production. Adding: compare.py:99
{
'details': {'bug': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1976286', 'who': '', 'why': '', 'name': '', 'created': ''},
'enabled': True,
'subject': 'MEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQ=',
'pubKeyHash': 'RGObk+I5lXFq77dZEeDHMb4KmhyXECijs4uez6wlLyM='
}
Staging is updated, and production changes are waiting, so Firefox can use compare.py:110
Remote Settings DevTools (https://github.com/mozilla-extensions/remote-settings-devtools)
and cert-storage-inspector (https://github.com/mozkeeler/cert-storage-inspector) to test
OneCRL.
Comment 6•1 year ago
|
||
As noted above, this entry was put into Remote Settings Production on August 11, 2025.
| Reporter | ||
Updated•1 year ago
|
| Reporter | ||
Updated•25 days ago
|
Description
•