Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

31–40 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#31
post #9

So, how much of my internet will break if I distrust the Symantec cert on my machine?

If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.

All sysadmins have nation-states as their threat model (or at least they should have it). If spy agencies can in any way leverage your network, then you're an automatic target.

https://theintercept.com/2014/03/20/inside-nsa-secret-effort...

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#32
post #29

Earlier quoted context omitted.

I'm hesitant to relax here. Blue Coat's got a nasty history of making money off of the regimes that'd do this without hesitation: https://www.newsrecord.co/us-based-internet-surveillance-tec...

Sure, but if they started issuing MitM certs ANYWHERE then Symantec would have no choice but to revoke the CA's certificate. It doesn't matter if the CA was functioning for a corrupt regime or a well-intentioned business legitimately MitM'ing employees traffic. If Symantec didn't revoke the certificate then it would almost certainly lead to their root certificate being untrusted by major browsers and destroy their en…

Between the time of issue and renovation, a lot of people can get arrested, monitored, or blackmailed.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#33

I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Even Cloudflare doesn't use their own CA, but they have a relationship with Comodo; at least, from what I can tell on services I use with Cloudflare.

If they just need to issue lots of certificates, or make it easy for client devices to get certificates, or even for their own cloud services, they could use LetsEncrypt.

There are very few use cases where having your own CA is necessary, and for a company like Blue Coat, those reasons seem primarily nefarious.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#34
post #30

Isn't the dead-line for Google removing Symantec from Chrome supposed to be this June? (if they don't adopt CT for all of their certificates by then, that is)

They are in the process of adopting it and emailing all their users to signup for CT.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#35
post #15

Earlier quoted context omitted.

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

I'm unclear about what you're saying. Are you saying it is OK for them to MITM traffic to https://google.com on their network by issuing a google.com cert? That is definitely not OK. If they only issue certs for domains that belong to themselves or their customers, that is OK.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#36
post #22
post #14

This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…

> In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. So why doesn't Blue Coat establish their own CA for this purpose?

Are you saying they should become a new root CA? That is a huge amount of work, and would require them to convince all browsers and OS's to make them a root CA, which many would be reluctant to do.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#37

https://archive.is/FEZfj just in case this goes down. How to untrust this certificate: https://blog.filippo.io/untrusting-an-intermediate-ca-on-os-...

Its funny how reluctant I am to install the certificate in the first step. I know it works as a vaccine of sorts, but still. It feels wrong.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#38

I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

> Symantec would get destroyed if they issued a CA cert that was misused, right?

Assuming browsers are willing to actually follow through and do so, yes.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#39
post #21
post #15

Earlier quoted context omitted.

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

Couldn't they implement something like cloudflare keyless ssl to keep this (horrible) ca private key... private?

This would keep the key private, but would not contain the potential for abuse. The appliance owner could still invoke whatever mechanism is used to generate certs for arbitrary hostnames.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#40
post #11

I wonder just how many certs I'd notice failing if I pulled Symantec's root out of my keystore - and if I'd get any mileage contacting the sites that end up broken and explaining why. This is exactly the sort of thing I'd like to have the "CA death penalty" seriously considered against Symantec - but I fear they're going to be judged "too big to fail". A grass roots campaign of contacting sites (especially sites I've…

IIRC Apple uses their own Root CA for signing updates and applications on the App Store + Gatekeeper-signed bundles.
Post reply on HN