Comodo revokes certificates without cause

Could you imagine a large company deceiving its clients, especially one that positions itself as a guardian of security? Until recently, I couldn't either. This article serves as a warning to think carefully before purchasing a code signing certificate from Comodo.

As part of my job (system administration), I create various useful programs that I actively use in my work and also share for free with anyone interested. About three years ago, it became necessary to sign applications; otherwise, not all my clients and users could download them smoothly just because they weren't signed. Signing has long been standard practice, and regardless of how safe an application is, if it isn't signed, it's bound to attract extra attention.

  1. The browser collects statistics on how often a file is downloaded, and when it is unsigned, it may even be blocked at the initial stage 'just in case', requiring explicit user confirmation to save it. Algorithms can vary; sometimes, the domain is considered trusted, but generally, a valid signature serves as confirmation of security.
  2. After downloading, the file is checked by antivirus software and, just before launching, by the operating system itself. The signature is also significant for antivirus software, which can be easily verified on virustotal, and as for the OS, starting from Windows 10, a file with a revoked certificate is immediately blocked and cannot be launched from File Explorer. Additionally, some organizations outright prohibit the execution of unsigned code (configured through system settings), and this is justified — all reputable developers have long ensured that their programs can be verified without extra effort.

Overall, the direction is correct — to make the internet as safe as possible for inexperienced users. However, the implementation is far from ideal. A regular developer cannot just obtain a certificate; it needs to be purchased from companies that have monopolized this market and dictate their terms. But what if the programs are free? That does not matter to anyone. Then the developer has a choice — to constantly prove the safety of their programs, sacrificing user convenience, or to buy a certificate. Three years ago, StartCom was viable, which is now lying at the bottom of the ocean, and there were never any issues with them. Currently, Comodo offers the lowest price, but as it turns out, there is a catch — for them, a developer is literally nobody, and scamming them is a standard practice.

After almost a year of using the certificate I purchased in mid-2018, Comodo suddenly revoked it without prior notice via email or phone, without explanation. Their support works poorly — they may not respond for a week; however, I managed to find out the main reason — they believed that the issued certificate was used to sign malware. And the story could have ended there if it weren't for one thing — I have never created malware, and my security methods confirm that it is impossible to steal my private key. A copy of the key is only with Comodo because they issue them without a CSR. And then — almost two weeks of unsuccessful attempts to obtain elementary proof. A company that supposedly guarantees protection in the security field flatly refused to provide proof of the violation of their rules.

From the last chat with supportYou 01:20
You have written «We strive to respond to standard support tickets within the same business day.» but I have been waiting for a response for a week now.

Vinson 01:20
Hi, Welcome to Sectigo SSL Validation!
Let me check your case status, please hold on for a minute.
I have checked and the order has been revoked due to malware/fraud/phishing by our higher official.

You 01:28
I am sure that this is your mistake, so I ask for proof.
I’ve never had malware/fraud/phishing.

Vinson 01:30
I am sorry, Alexander. I have double checked and the order has been revoked due to malware/fraud/phishing by our higher official.

You 01:31
In which file did you see the virus? Is there a link to virustotal? I do not accept your answer because there is no proof in it. I paid money for this certificate and I have the right to know why my money is taken from me by force.
If you cannot provide proof, then the certificate was unfairly revoked and the money must be refunded. Otherwise, what is the purpose of your work if you revoke certificates without evidence?

Vinson 01:34
I understand your concern. The code signing certificate has been reported for distributing malware. According to industry guidelines, Sectigo as a Certificate Authority is obligated to revoke the certificate.
Furthermore, according to the refund policy, we will not be able to issue a refund after 30 days from the date of issuance.

You 01:35
Why do you believe this is not a mistake or a false positive?

Vinson 01:36
I am sorry, Alexander. According to our higher officials' report, the order has been revoked due to malware/fraud/phishing.

You 01:37
There's no need to apologize; I paid the money and I want to see proof that I violated your rules. It’s straightforward.
I paid for three years, then you provided a reason and left me without a certificate and without proof of my wrongdoing.

Vinson 01:43
I understand your concern. The code signing certificate has been reported for distributing malware. According to industry guidelines, Sectigo as a Certificate Authority is obligated to revoke the certificate.

You 01:45
It seems you do not understand. Where have you seen a court passing a sentence without evidence? You did just that. I have never had malware. Why do you not provide proof if it exists? What specific proof does certificate revocation entail?

Vinson 01:46
I am sorry, Alexander. According to our higher officials' report, the order has been revoked due to malware/fraud/phishing.

You 01:47
Who can I contact to find out the real reason for revoking the certificate?
If you cannot answer, tell me whom to contact.

Vinson 01:48
Please submit a ticket again using the link below so that you can receive a response as soon as possible.
sectigo.com/support-ticket

You 01:48
Thank you.
This is not an isolated incident; throughout the chat negotiations, the best response received is always the same, and either there are no replies to the tickets or the responses are equally useless.

Creating the ticket againMy request:
I require proof that I violated a rule leading to the revocation. I bought a certificate and want to know why my money was taken from me.
‘malware/fraud/phishing’ is not the answer! In which file did you find the virus? Is there a link to VirusTotal? Please provide proof or return my money; I’m tired of writing to technical support and have been waiting for more than a week.
Thank you.

Their response:
The code signing certificate has been reported for distributing malware. According to industry guidelines, Sectigo as a Certificate Authority is obligated to revoke the certificate.
Hope of receiving a response from someone competent is rapidly fading. An interesting scheme emerges:

  1. We sell the certificate.
  2. We wait more than half a year until it becomes impossible to file a dispute through PayPal.
  3. We revoke and await the next order. Profit!

Since I have no other means of influence, I can only expose their fraud. Purchasing a certificate from Comodo, also known as Sectigo, may lead to a similar situation.

Update from June 9:
Today, I informed CodeSignCert (the company through which I purchased the certificate) that since they stopped responding, I would be bringing this situation to public attention with a link to this article. After some time, they finally sent a screenshot from VirusTotal showing the hash of the program. EzvitUpd:
VirusTotal — d92299c3f7791f0ebb7a6975f4295792fbbf75440cb1f47ef9190f2a4731d425

My assessment of the situation:
I can confidently say that this is a false positive. Signs:

  1. The Generic designation in most detections.
  2. No detections from leading antivirus providers.

It's hard to say what exactly triggered such a reaction from antivirus programs, but since the file is quite outdated (created almost a year ago), I do not have the source for version 1.6.1 to recreate the file binarily. However, I have the latest version 1.6.5, and given the invariance of the main branch, the changes made were minimal, but there is no such false positive associated with it:
VirusTotal — c247d8c30eff4449c49dfc244040fc48bce4bba3e0890799de9f83e7a59310eb

CodeSignCert has been informed of the false positive, and the article will be updated as further negotiation results appear to fully resolve the situation.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster