Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

61–70 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#61
post #41

Earlier quoted context omitted.

Banks can just switch to better SSL services...

Any large organization lacks the ability to "just switch" from one thing to another.

I agree.

However, there's no point in pretending these certs are good if we can't trust the issuer to not put out BAD certs. Painful or not, if the banks are user the certs to show they are trustworthy, then they need to switch when the issuer ISN'T trustworthy.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#62
post #38

Earlier quoted context omitted.

I think it's likelier that Symantec will start a negative PR campaign, leading its users to yell at google to change things, perhaps calling this FUD. Whether that'll be effective is another question.

>Symantec will start a negative PR campaign, leading its users to yell at google to change things, It seems Google has the leverage, not Symantec. A PR awareness campaign is out-of-band information that's separate from the web surfer actually navigating to a site. Millions of users would see a scary message similar to "This site's security certificate is not trusted!" [1]. To prevent scary security popups, which is m…

or

3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites.

I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#63
post #54

TLDR: for the next few months, expect to tell your relatives "just click yes on the big red warning dialog". Not sure if this is good conditioning.

The schedule they're proposing tries to specifically avoid as much of this as possible. This is probably as close to "no impact for average users" as you can get if you don't want to accept that too-big-to-fail is a thing in the Web PKI.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#65

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

Well, Comodo's had an okay track-record, if I recall correctly. But I also don't recall them being cheap.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#67

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

Well, Comodo's had an okay track-record, if I recall correctly. But I also don't recall them being cheap.

i have been seriously considering comodo. Their wildcard is not priced all that bad.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#68
post #50
post #41

Earlier quoted context omitted.

Banks can just switch to better SSL services...

ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…

>especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I have ever seen that before, no one would be that foolish right? :/)

D'ya know, I would have naively assumed this wasn't technically possible. I shudder not only to think of the code, but also of the thought process that could compel someone to undergo the effort of bricking themselves into this corner because honestly, that sounds a lot harder than doing it right.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#69

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

> Anybody know what are the remaining, trustworthy certificate issuers ?

You could take a look at Gandi.net. I don't have any experience with their Certificates, but I trust them with the all their other offerings.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#70
post #64

What's Mozilla doing?

https://groups.google.com/forum/#!topic/mozilla.dev.security...

As far as I can tell, discussion about what to do with Symantec was ongoing, Google didn't think the outcome was going to be what they wanted, and then enacted a different policy on their own.

Post reply on HN