Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

1–10 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#2
I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates.

It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers, but given their own checkered history[2] I don't think it would be unreasonable to suggest they're going to use this for MITM purposes.

[1] - https://security.googleblog.com/2015/09/improved-digital-cer...

[2] - https://en.wikipedia.org/w/index.php?title=Blue_Coat_Systems...

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#6

https://archive.is/FEZfj just in case this goes down. How to untrust this certificate: https://blog.filippo.io/untrusting-an-intermediate-ca-on-os-...

Instructions from parent are OSX only. Here's a post covering Windows and Firefox, which has its own certificate store:

http://netsekure.org/2010/04/how-to-disable-trusted-root-cer...

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#10

I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right?

Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Post reply on HN