I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…
Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
41–50 of 118 posts
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#42Earlier quoted context omitted.
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
If you want to MITM traffic on your network, have clients install your MITM certificate, which gives them ample warning about what you're doing.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#43Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#44Earlier quoted context omitted.
> In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. So why doesn't Blue Coat establish their own CA for this purpose?
Are you saying they should become a new root CA? That is a huge amount of work, and would require them to convince all browsers and OS's to make them a root CA, which many would be reluctant to do.
Legitimate uses of this would be things like government or military departments intercepting traffic from their own network.
As explained elsewhere in this thread, they have a history of working with regimes where they want to intercept the traffic of the general public in countries.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#45Earlier quoted context omitted.
Sure - but from the (to be taken with appropriate credibility rating) WikiPedia page for BlueCoat: "Blue Coat products are primarily used by enterprises, schools, hospitals, governments, and public agencies to block malware and malicious threats, control access to applications and content in the workplace, surveillance, censorship, and improve the performance of network applications." I'm resigned to acknowledging th…
Ok, so if your adversary is your employer or your school, you are presumably using a network not controlled by you, in which case your endpoint ought to already be a VPN. A good number of employer or school-provider devices will have their own certificates preinstalled anyway. Nobody ever said privacy was convenient.
I'm _not good with a school or employer's network being able to generate arbitrary certs for my email, bank, social networks, etc - WITHOUT ME KNOWING ABOUT IT ON MY PERSONAL DEVICES... Sure, MitM me if it's your network - but I 100% should be able to rely on my browser on my device reliably being able to tell me "You're attempting to visit https://mybank.com, but the certificate identifies it as mybank.suspiciouscorp.net Continue anyway (not recommended): [OK] [Hell no!]"
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#46I wonder just how many certs I'd notice failing if I pulled Symantec's root out of my keystore - and if I'd get any mileage contacting the sites that end up broken and explaining why. This is exactly the sort of thing I'd like to have the "CA death penalty" seriously considered against Symantec - but I fear they're going to be judged "too big to fail". A grass roots campaign of contacting sites (especially sites I've…
Maybe a browser extension that generates this email automatically to automatically send to the screen-scraped contact-us web email address/form? "Hi, I use bigiainDisconnectAdblockPlus-thingy and just wanted to let you know I didn't visit your site because I can't trust your certificates, which come from Symantec. Here's the fingerprint of that cert xxxxxxxxxxxxxxxxx and here's why I can't trust it "
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#47Earlier quoted context omitted.
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
> Symantec would get destroyed if they issued a CA cert that was misused, right? Assuming browsers are willing to actually follow through and do so, yes.
My guess is they'd settle for blocking certs issued after a specific date, at least for a transition period. The alternative would block too much of the internet.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#48Earlier quoted context omitted.
> Symantec would get destroyed if they issued a CA cert that was misused, right? Assuming browsers are willing to actually follow through and do so, yes.
The big question is does the emperor have any clothes? My guess is they'd settle for blocking certs issued after a specific date, at least for a transition period. The alternative would block too much of the internet.
At a minimum they could block EV certs from being honoured as EV which harms reputation and prevents a profitable line of business.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#49This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#50Earlier quoted context omitted.
Sure, but if they started issuing MitM certs ANYWHERE then Symantec would have no choice but to revoke the CA's certificate. It doesn't matter if the CA was functioning for a corrupt regime or a well-intentioned business legitimately MitM'ing employees traffic. If Symantec didn't revoke the certificate then it would almost certainly lead to their root certificate being untrusted by major browsers and destroy their en…
Between the time of issue and renovation, a lot of people can get arrested, monitored, or blackmailed.