Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

11–20 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#11
I wonder just how many certs I'd notice failing if I pulled Symantec's root out of my keystore - and if I'd get any mileage contacting the sites that end up broken and explaining why.

This is exactly the sort of thing I'd like to have the "CA death penalty" seriously considered against Symantec - but I fear they're going to be judged "too big to fail". A grass roots campaign of contacting sites (especially sites I've got paid accounts with) saying "Sorry, I can't use your site anymore because I've had to disable Symantec's root keys (see this link for reasons), can I please cancel my billing." might be the only thing I can do.

(Oh, and joy! https://www.apple.com is secured by a Symantec cert for me right now. How much would you bet against all my Mac OS X and iOS software updates also being "secured" that way?)

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#12
post #9

So, how much of my internet will break if I distrust the Symantec cert on my machine?

If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place.

With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#13
What was Symantec thinking? Doing decisions that undermine their whole business?

Unless there's something that can explain this in better light, it's time to untrust Symantec brands and stop purchasing their certificates. Is it really that VeriSign, one of the pioneers in CA industry, cannot be trusted anymore?

Remember that also Thawte is their brand.

Incredible.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#14
This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate.

That said, I'm quite curious though if Google is going to require that Blue Coat submit all issued certificates to be submitted to Certificate Transparency logs like the rest of Symantec's certificates[0].

[0] https://security.googleblog.com/2015/10/sustaining-digital-c...

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#15

I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud...

In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they have the right to operate it the way they want.

Any other use of the intermediate CA would be highly irresponsible/dangerous. For example if they used it in their SSL Visibility Appliance, any owner of the appliance could extract the CA private key from the appliance.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#16
post #9

So, how much of my internet will break if I distrust the Symantec cert on my machine?

If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.

Sure - but from the (to be taken with appropriate credibility rating) WikiPedia page for BlueCoat:

"Blue Coat products are primarily used by enterprises, schools, hospitals, governments, and public agencies to block malware and malicious threats, control access to applications and content in the workplace, surveillance, censorship, and improve the performance of network applications."

I'm resigned to acknowledging that if the NSA (GHCQ/ASD/insert-local-equivalent at least for five-eyes nations) wants to investigate _me_ specifically, I'm fucked and my only option is to not use the internet (or telephones or mail or or or).

I'm not (yet) prepared to give up and hand that level of access to my digital life to enterprises, schools, (most bits of the) government, or public agencies.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#17
post #11

I wonder just how many certs I'd notice failing if I pulled Symantec's root out of my keystore - and if I'd get any mileage contacting the sites that end up broken and explaining why. This is exactly the sort of thing I'd like to have the "CA death penalty" seriously considered against Symantec - but I fear they're going to be judged "too big to fail". A grass roots campaign of contacting sites (especially sites I've…

Maybe a browser extension that generates this email automatically to automatically send to the screen-scraped contact-us web email address/form? "Hi, I use bigiainDisconnectAdblockPlus-thingy and just wanted to let you know I didn't visit your site because I can't trust your certificates, which come from Symantec. Here's the fingerprint of that cert xxxxxxxxxxxxxxxxx and here's why I can't trust it "

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#18
post #9

So, how much of my internet will break if I distrust the Symantec cert on my machine?

If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.

I would think that there's a difference between a nation-state targetting me sprcifically, and one running a general dragnet.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#19
post #14

This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…

I'm hesitant to relax here. Blue Coat's got a nasty history of making money off of the regimes that'd do this without hesitation:

https://www.newsrecord.co/us-based-internet-surveillance-tec...

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#20

Earlier quoted context omitted.

If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.

I would think that there's a difference between a nation-state targetting me sprcifically, and one running a general dragnet.

Snowden's shown us it's not quite as clear-cut as that, but yeah.
Post reply on HN