Live data from Hacker News

Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

sslmate.com

81–90 of 95 posts

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#81
post #59

Earlier quoted context omitted.

It actually is almost nothing like the auto updating feature. Finch is mainly used for A/B testing. It doesn't push actual updates, all it does it turn existing features (flags) on and off. It's used for quickly A/B testing or incremental rolling new features and is designed to be more agile.

That means it uniquely identified you to Google every day then, right?

> using a Google browser

> not wanting to be tracked

here's a hint: ad impression for unknown user is 0.01$ and for logged in user 2$. guess why Google has a browser now...

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#82
post #24
post #22

Author here. It has gotten kind of hard to follow what has happened, so here's a chronology: 1. In September, Chrome 53 was released, which enabled mandatory Certificate Transparency for Symantec certificates due to Symantec's history of incompetence. Some website operators, such as Chase, asked Symantec to submit their certificates to Certificate Transparency logs in such a way that the certificate wouldn't be trust…

Is there any reason, in 2016, to use Symantec over LetsEncrypt?

The Symantec "this website is ssl protected by"-badge has high customer recognition and will raise conversion rates a tenth of a percent or two.

If I hadn't seen it repeatedly with my own eyes - most trust images will get you a small bump, for some reason Symantec performs the best. It's understandable and yet very frustrating!

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#83
post #24

Earlier quoted context omitted.

Is there any reason, in 2016, to use Symantec over LetsEncrypt?

For small startups, probably not. Large organisations have far more stringent processes around certificates. Auditing, validation, testing, regulatory requirements, EV, support contracts and SLAs, etc.

yet all that don't add absolute any value to the company nor security to their data. since they're still paying a vendor full of problems.

incompetence promoting incompetence. the staple of big corporations.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#85

Earlier quoted context omitted.

» When Chrome starts up, it fetches a list of feature flags from a Chrome server using a system called Finch which is independent of the normal upgrade system. I'm not a Chrome user. But that sounds awful at first. What is the idea behind this service? Is there any documentation about the 'features' these flags can enable/disable? I understand that I'm paranoid at times AND I really dislike Google, but why would you…

I fail to see this as any more harmful than the auto updating feature. I understand the concern of multiple avenues to phone home as being worse than one, but it's negligible considering it's the same company. Coupled with all of their other services for security incidents, prediction, auto correct, spelling, usage stats, dangerous page warnings, etc, I think it's just another log on the fire and not worth being conc…

The biggest difference I see is the speed. You're right, it doesn't make a difference from a technical point of view but it illustrates again just how much power they have over chrome - and thereby over the web: They can push a policy update to the bigger part of Chrome's userbase in 24 hours.

It should be entertaining when car makers use the same strategy: "Oh yeah, we have this system where everytime you turn the ignition, your car polls us and updates its assistant, motor, steering and airbag settings. Don't worry though, we mostly just use it for randomized tests and field trials."

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#86
post #59

Earlier quoted context omitted.

It actually is almost nothing like the auto updating feature. Finch is mainly used for A/B testing. It doesn't push actual updates, all it does it turn existing features (flags) on and off. It's used for quickly A/B testing or incremental rolling new features and is designed to be more agile.

That means it uniquely identified you to Google every day then, right?

Does it? Does the request actually provide enough to uniquely identify you?

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#87

Earlier quoted context omitted.

Well I suppose curl/wget will never be RFC compliant user agents (curl -k, wget --no-check-certificate). But somehow I think they'll still be used...

wget writes a ~/.wget-hsts file with the HSTS information for any URI you have accessed that served an HSTS header. Making it ignore --no-check-certificate if the file has an entry for the hostname you are visiting should be trivial, if it hasn't been done already.

Exactly.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#88
post #24

Earlier quoted context omitted.

Is there any reason, in 2016, to use Symantec over LetsEncrypt?

When it comes to Certificate Transparency, LE doesn't bed SCTs in the issued certificates, which is mildly annoying.

Practically speaking, this has no impact until browsers start requiring CT (which is in about a year for Chrome).

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#89
post #24
post #22

Author here. It has gotten kind of hard to follow what has happened, so here's a chronology: 1. In September, Chrome 53 was released, which enabled mandatory Certificate Transparency for Symantec certificates due to Symantec's history of incompetence. Some website operators, such as Chase, asked Symantec to submit their certificates to Certificate Transparency logs in such a way that the certificate wouldn't be trust…

Is there any reason, in 2016, to use Symantec over LetsEncrypt?

Apart from the reasons posted earlier, "legacy" also comes into play.

Symantec acquired the CA business from the old VeriSign in 2010, which back then was the largest CA and had a large corporate client portfolio accustomed to paying $$$$ per certificate per year. Corporations can become very reluctant to change, even if it benefits them, and there are some who just pay up every year without researching alternatives or even being aware of any.

You will find that there are a lot of similarities with the domain name industry where there is also a company operating with a VeriSign heritage: Network Solutions. Network Solutions also charge premium prices, because their legacy customers expect those. And although market share is slowly eroding over the years and cheap (and even free) competitors rise, more than enough legacy customers stay on board to remain very profitable for many years to come. What definitely helps is that most of the processes in the domain registration and CA industries can be automated and don't need a lot of maintenance.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#90
post #24

Earlier quoted context omitted.

Is there any reason, in 2016, to use Symantec over LetsEncrypt?

The Symantec "this website is ssl protected by"-badge has high customer recognition and will raise conversion rates a tenth of a percent or two. If I hadn't seen it repeatedly with my own eyes - most trust images will get you a small bump, for some reason Symantec performs the best. It's understandable and yet very frustrating!

It's not "Symantec", it's not "Norton", it's the "VeriSign checkmark". That's why they also bought the checkmark from VeriSign (which was also their corporate logo) when they acquired the CA business, and VeriSign went on and adopted a new corporate logo.

The checkmark been around since at least 1997, and in it existence it has been associated with the most trustworthy institutions. It has become a synonym of trust. That checkmark is one of Symantec's most valuable assets.

Post reply on HN