Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

91–100 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#91
Anyone have any more information on the incidents that triggered this response? I was able to find this article on Google's Security Blog: https://security.googleblog.com/2015/10/sustaining-digital-c...

But that's almost 2 years old. Have there been any more recent incidents that I'm unaware of?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#92
post #42
post #37

Are they just hoping to drive business to their new CA: Google Trust Services?

That's unlikely, as they currently do not offer certificates to the general public. I imagine if they do at some point, it might be as part of something like their version of Amazon's ACM for their Cloud offerings, or for custom domains on sites like Blogger. I'd expect both to be free. They're also a platinum sponsor of Let's Encrypt.

This happened recently with all my free StartSSL / Startcom certificates. I switched to LetsEncrypt. Also noticing Google and Mozilla's sponsorship.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#93
post #60

Earlier quoted context omitted.

Any large organization lacks the ability to "just switch" from one thing to another.

I'm fairly sure at least some of the "policy violations" that Symantec did were done exactly as a service to their large bank-or-close-enough customers. It's not that banks want to switch to a "better" SSL service, it's Symantec being a "better" service for them that got Symantec into trouble. (IIRC, from reading some of the incident reports)

Can you name some specific examples?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#94
post #91

Anyone have any more information on the incidents that triggered this response? I was able to find this article on Google's Security Blog: https://security.googleblog.com/2015/10/sustaining-digital-c... But that's almost 2 years old. Have there been any more recent incidents that I'm unaware of?

https://groups.google.com/forum/#!forum/mozilla.dev.security...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#95
But why is https://w3techs.com/technologies/history_overview/ssl_certif... saying Let’s Encrypt has 0.1% when https://letsencrypt.org/stats/ says 32 million Fully-Qualified Domains Active?

32 million = 0.1% 32 000 million SSL certs? = 100%

? what?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#97
post #77

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

I have heard lots of good things about Digicert, FWIW. No personal experience as my use case can be covered by LetsEncrypt.

Digicert works for us. Wouldn't mind switching to LetsEncrypt but vendors are the issue (oh, the joy of approved lists).

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#98

Earlier quoted context omitted.

How recently did you renew? This has been in the works for over two years,I'm surprised that anyone is still giving them business.

We renewed recently, through our hosting provider who have Symantec in their certificate chain.

I would contact your hosting provider. They are going to have to find a new CA themselves and when they do, I would guess they would be willing to mint you a new EV cert.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#99
post #91

Anyone have any more information on the incidents that triggered this response? I was able to find this article on Google's Security Blog: https://security.googleblog.com/2015/10/sustaining-digital-c... But that's almost 2 years old. Have there been any more recent incidents that I'm unaware of?

https://www.mail-archive.com/dev-security-policy@lists.mozil...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#100

But why is https://w3techs.com/technologies/history_overview/ssl_certif... saying Let’s Encrypt has 0.1% when https://letsencrypt.org/stats/ says 32 million Fully-Qualified Domains Active? 32 million = 0.1% 32 000 million SSL certs? = 100% ? what?

The Let's Encrypt roots were cross-signed by IdenTrust, who are number 2 in that table.
Post reply on HN