Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

41–50 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#41

TLDR: Google has lost trust in Symantec's ability to properly validate certificates they issue. Chrome has a Root Certificate Policy that expects a CA to perform in a manner commensurate with the trust being placed in them and the Google team appears to see evidence that they are not living up to the standard laid out. They propose a gradual distrust of existing certificates by reducing the 'maximum age' of the certi…

They're also planning on stripping EV status from their Certs too... that's going to be fun for a lot of banks.

Banks can just switch to better SSL services...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#42
post #37

Are they just hoping to drive business to their new CA: Google Trust Services?

That's unlikely, as they currently do not offer certificates to the general public. I imagine if they do at some point, it might be as part of something like their version of Amazon's ACM for their Cloud offerings, or for custom domains on sites like Blogger. I'd expect both to be free. They're also a platinum sponsor of Let's Encrypt.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#43
post #36
post #23

Earlier quoted context omitted.

They can improve security. We used to pin the EV roots of a couple CAs that we trusted in our mobile apps and in the browser via hpkp. This protected against someone tricking or coercing a lesser CA into issuing a DV cert and MITMing us.

Why does EV make a difference here? Can't you pin an intermediate or root cert from your CA of choice and avoid other CAs issuing end certs for your domain just as well?

I think the idea here is that they're not trying to prevent other CAs from issuing end certs, they're trying to only allow certs for their domain - from any CA on their short list - if the owner of the cert has been through Extended Validation.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#44
post #22

Earlier quoted context omitted.

As the neighbor comment points out, EV validation is absolutely not a waste of money. I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. They don't improve security -- that is true.

> I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. That's a bit hard to reconcile with the fact that Amazon.com can't be bothered to get one.

amazon has brand recognition, they don't need to assuage people's semi-conscious perception of site trustworthyness.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#45
post #22

Earlier quoted context omitted.

As the neighbor comment points out, EV validation is absolutely not a waste of money. I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. They don't improve security -- that is true.

> I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. That's a bit hard to reconcile with the fact that Amazon.com can't be bothered to get one.

Most outliers are hard to reconcile with the mean.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#46
post #24
post #17

Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…

> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

"Baseline Requirements" sort of implies that what is specified is minimum, rather than exhaustive, rules, and that specific applications will have additional rules.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#47
post #41

Earlier quoted context omitted.

They're also planning on stripping EV status from their Certs too... that's going to be fun for a lot of banks.

Banks can just switch to better SSL services...

Any large organization lacks the ability to "just switch" from one thing to another.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#49
>All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding.

>While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact

Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ?

No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places)

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#50
post #41

Earlier quoted context omitted.

They're also planning on stripping EV status from their Certs too... that's going to be fun for a lot of banks.

Banks can just switch to better SSL services...

ha.ha.ha.

I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today.

SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I have ever seen that before, no one would be that foolish right? :/)

Post reply on HN