Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

51–60 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#51
post #29
post #3

Earlier quoted context omitted.

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

users will start getting instructed by sites that they have to manually add a root certificate in order to use they site Or switch browsers. Google needs to (and will) play this so it ends up being unattractive for other browser vendors not to distrust Symantec as well.

That's a good insight. Apple and Mozilla don't seem to mind making big decisions for their users on behalf of perceived security threats either, so I imagine only Edge will hold out for long time. Google probably won't lose any market share over this.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#52

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

> No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places)

Why does that matter? Pretty sure you don't have to change your public key to get or renew a Let's Encrypt cert.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#53
I was curious if this would affect my Symantec issued certs... according to my date math:

Chrome 59 (Apr 13, 2017) +1023 days: 2020-01-31

Chrome 60 (May 25th, 2017) +837 days: 2019-09-09

Chrome 61 (Jul 20th, 2017) +651 days: 2019-05-02

Chrome 62 (Aug 31st, 2017) +465 days: 2018-12-09

Chrome 63 (Oct 12th, 2017) +279 days: 2018-07-18

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#56
post #25

What is the chrome release schedule? i.e. what is the timeline for the 59 - 64 releases to happen? A quick google isn't getting me an answer(and I don't use Chrome, so don't really pay attention).

What'd you search for? I typed in: chrome release schedule and this was the first link: https://www.chromium.org/developers/calendar .

Thanks! My date math says:

Chrome 59 (Apr 13, 2017) certs invalid after 2020-01-31

Chrome 60 (May 25th, 2017) certs invalid after 2019-09-09

Chrome 61 (Jul 20th, 2017) certs invalid after 2019-05-02

Chrome 62 (Aug 31st, 2017) certs invalid after 2018-12-09

Chrome 63 (Oct 12th, 2017) certs invalid after 2018-07-18

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#57
post #26
post #15

Earlier quoted context omitted.

I for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.

EV certificates have the same level of confidentiality and integrity as DV certs, but they have different authentication - specifically, they tie the certificate to a legal entity rather than a domain name. ie. https://paypal.com-customerservice.ru vs PayPal Inc [US] | https://paypal.com I run https://certsimple.com . We sell EV certs. But you can verify the above pretty easily by checking out the EV guidelines, the…

I'm bookmarking your page for when I need it...

But that overlay just before I started reading your landing text is a serious mood-killer. I'm not going to set-up a remainder for when my certificate expires before I read your page.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#58

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

You can use an existing CSR with Let's Encrypt, so you wouldn't have to change your public key.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#59
post #52

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

> No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places) Why does that matter? Pretty sure you don't have to change your public key to get or renew a Let's Encrypt cert.

we spawn our servers and scale them up and down. We terminate ssl internally to our applications which are on Docker.

Letsencrypt is painful on docker. I dont mind paying 40$ per year for a wildcard ssl certificate.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#60
post #41

Earlier quoted context omitted.

Banks can just switch to better SSL services...

Any large organization lacks the ability to "just switch" from one thing to another.

I'm fairly sure at least some of the "policy violations" that Symantec did were done exactly as a service to their large bank-or-close-enough customers.

It's not that banks want to switch to a "better" SSL service, it's Symantec being a "better" service for them that got Symantec into trouble.

(IIRC, from reading some of the incident reports)

Post reply on HN