Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

71–80 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#71
post #41

Earlier quoted context omitted.

Banks can just switch to better SSL services...

Any large organization lacks the ability to "just switch" from one thing to another.

Not always, although it depends on what you are changing. I work for a 200,000 person company, and switching cert providers would not be a huge task. We have done it before.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#72
post #24
post #17

Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…

> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

> Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

In any industry where a single actor has a clear majority of the market share, you either vote with your feet (and implore all your friends to do so as well) to bring the powers back into equilibrium, or you cross your fingers and pray that Goliath is (and remains) benevolent.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#74

Earlier quoted context omitted.

Well, Comodo's had an okay track-record, if I recall correctly. But I also don't recall them being cheap.

i have been seriously considering comodo. Their wildcard is not priced all that bad.

According to the this survey I'm ruthlessly stealing from another comment, they have the biggest market share right now: https://w3techs.com/technologies/history_overview/ssl_certif...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#76
I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust?

For the vast majority of users that's probably just fine, but I would have thought that there'd be a browser or extension or something that allows security-conscious power users more fine-grained control over this by now.

For example, I could subscribe to changes in CA trust levels from every major browser vendor, and if they don't agree my browser could show me a warning with an explanation.

Or I could subscribe to feeds from other entities I trust, like the EFF. Or my security-conscious friends.

Or if I decide I have lower trust in certificates issued by governmental CAs, or CAs in certain regions, I could mark them as lower trust.

Basically a web of trust for CAs.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#77

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

I have heard lots of good things about Digicert, FWIW. No personal experience as my use case can be covered by LetsEncrypt.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#78
post #53

I was curious if this would affect my Symantec issued certs... according to my date math: Chrome 59 (Apr 13, 2017) +1023 days: 2020-01-31 Chrome 60 (May 25th, 2017) +837 days: 2019-09-09 Chrome 61 (Jul 20th, 2017) +651 days: 2019-05-02 Chrome 62 (Aug 31st, 2017) +465 days: 2018-12-09 Chrome 63 (Oct 12th, 2017) +279 days: 2018-07-18

If I'm reading the post right, it's stricter than that:

> ...distrusting certificates whose validity period (the difference of notBefore to notAfter) exceeds the specified maximum.

I.e., a certificate valid from 1/2015..1/2019 is distrusted as of Chrome 59.

And the more lax restrictions only apply to certificates that have already been issued. Any one issued after Chrome 61 are held to the highest (9 mo) limit.

> In addition, we propose to require that all newly-issued certificates must have validity periods of no greater than 9 months (279 days) in order to be trusted in Google Chrome, effective Chrome 61.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#79
post #24
post #17

Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…

> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

You wouldn't want a standards group that somehow mandates all clients must accept all valid certs, right?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#80
post #38

Earlier quoted context omitted.

>Symantec will start a negative PR campaign, leading its users to yell at google to change things, It seems Google has the leverage, not Symantec. A PR awareness campaign is out-of-band information that's separate from the web surfer actually navigating to a site. Millions of users would see a scary message similar to "This site's security certificate is not trusted!" [1]. To prevent scary security popups, which is m…

or 3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites. I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.

>Large websites using Symantec certs start telling users Chrome is "broken"

I'm having a hard time thinking of a scenario where a large website concludes it's cheaper to convince web shoppers at ecommerce sites and web visitors at news sites to switch to Firefox/IE instead of the website just switching CA vendors.

If you're a website that wants to put up zero friction between buyers submitting their credit-card info and pay you money, why try to "educate" them? If you're a website that wants visitors to see your ads next to your journalists' stories, why make it more difficult than it has to be? Does Symantec as a CA offer up extra benefits that no other CA has such that it makes sense to "train" web visitors to switch browsers?

Of the millions of non-geeks that use Android phones, what % download and use Firefox instead of the default Chrome browser?

Post reply on HN