Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

21–30 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#21
post #15

Earlier quoted context omitted.

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

Couldn't they implement something like cloudflare keyless ssl to keep this (horrible) ca private key... private?

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#22
post #14

This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…

> In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate.

So why doesn't Blue Coat establish their own CA for this purpose?

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#23
post #14

This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…

This is a baby step in the direction of legitimate MITMing of SSL, which is something many of Blue Coat's customers would love. SSL's entire security profile is built around trust in a huge number of CAs, and if Blue Coat and other can persuade one to allow this in any form then SSL is fundamentally and permanently broken (without pinning or out of band checks) for pretty much all users except highly technical ones.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#24
post #15

Earlier quoted context omitted.

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

> In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they have the right to operate it the way they want.

Even that is silly - they don't need to be an intermediate CA to do that. Just require that their customers install a custom certificate.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#25
post #16

Earlier quoted context omitted.

If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.

Sure - but from the (to be taken with appropriate credibility rating) WikiPedia page for BlueCoat: "Blue Coat products are primarily used by enterprises, schools, hospitals, governments, and public agencies to block malware and malicious threats, control access to applications and content in the workplace, surveillance, censorship, and improve the performance of network applications." I'm resigned to acknowledging th…

Ok, so if your adversary is your employer or your school, you are presumably using a network not controlled by you, in which case your endpoint ought to already be a VPN.

A good number of employer or school-provider devices will have their own certificates preinstalled anyway.

Nobody ever said privacy was convenient.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#27

I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

[deleted]

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#29
post #14

This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…

I'm hesitant to relax here. Blue Coat's got a nasty history of making money off of the regimes that'd do this without hesitation: https://www.newsrecord.co/us-based-internet-surveillance-tec...

Sure, but if they started issuing MitM certs ANYWHERE then Symantec would have no choice but to revoke the CA's certificate. It doesn't matter if the CA was functioning for a corrupt regime or a well-intentioned business legitimately MitM'ing employees traffic.

If Symantec didn't revoke the certificate then it would almost certainly lead to their root certificate being untrusted by major browsers and destroy their entire certificate business.

Post reply on HN