Earlier quoted context omitted.
Banks can just switch to better SSL services...
Any large organization lacks the ability to "just switch" from one thing to another.
Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
71–80 of 329 posts
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#72Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…
> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways
In any industry where a single actor has a clear majority of the market share, you either vote with your feet (and implore all your friends to do so as well) to bring the powers back into equilibrium, or you cross your fingers and pray that Goliath is (and remains) benevolent.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#73Is there a list anywhere of which EV cert providers use Symantec as a CA?
http://pastebin.com/raw/nUEq5cFP
Not sure if all of them issue EV.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#74Earlier quoted context omitted.
Well, Comodo's had an okay track-record, if I recall correctly. But I also don't recall them being cheap.
i have been seriously considering comodo. Their wildcard is not priced all that bad.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#75Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#76For the vast majority of users that's probably just fine, but I would have thought that there'd be a browser or extension or something that allows security-conscious power users more fine-grained control over this by now.
For example, I could subscribe to changes in CA trust levels from every major browser vendor, and if they don't agree my browser could show me a warning with an explanation.
Or I could subscribe to feeds from other entities I trust, like the EFF. Or my security-conscious friends.
Or if I decide I have lower trust in certificates issued by governmental CAs, or CAs in certain regions, I could mark them as lower trust.
Basically a web of trust for CAs.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#77> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#78I was curious if this would affect my Symantec issued certs... according to my date math: Chrome 59 (Apr 13, 2017) +1023 days: 2020-01-31 Chrome 60 (May 25th, 2017) +837 days: 2019-09-09 Chrome 61 (Jul 20th, 2017) +651 days: 2019-05-02 Chrome 62 (Aug 31st, 2017) +465 days: 2018-12-09 Chrome 63 (Oct 12th, 2017) +279 days: 2018-07-18
> ...distrusting certificates whose validity period (the difference of notBefore to notAfter) exceeds the specified maximum.
I.e., a certificate valid from 1/2015..1/2019 is distrusted as of Chrome 59.
And the more lax restrictions only apply to certificates that have already been issued. Any one issued after Chrome 61 are held to the highest (9 mo) limit.
> In addition, we propose to require that all newly-issued certificates must have validity periods of no greater than 9 months (279 days) in order to be trusted in Google Chrome, effective Chrome 61.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#79Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…
> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#80Earlier quoted context omitted.
>Symantec will start a negative PR campaign, leading its users to yell at google to change things, It seems Google has the leverage, not Symantec. A PR awareness campaign is out-of-band information that's separate from the web surfer actually navigating to a site. Millions of users would see a scary message similar to "This site's security certificate is not trusted!" [1]. To prevent scary security popups, which is m…
or 3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites. I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.
I'm having a hard time thinking of a scenario where a large website concludes it's cheaper to convince web shoppers at ecommerce sites and web visitors at news sites to switch to Firefox/IE instead of the website just switching CA vendors.
If you're a website that wants to put up zero friction between buyers submitting their credit-card info and pay you money, why try to "educate" them? If you're a website that wants visitors to see your ads next to your journalists' stories, why make it more difficult than it has to be? Does Symantec as a CA offer up extra benefits that no other CA has such that it makes sense to "train" web visitors to switch browsers?
Of the millions of non-geeks that use Android phones, what % download and use Firefox instead of the default Chrome browser?