Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

101–110 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#101
post #60

Earlier quoted context omitted.

I'm fairly sure at least some of the "policy violations" that Symantec did were done exactly as a service to their large bank-or-close-enough customers. It's not that banks want to switch to a "better" SSL service, it's Symantec being a "better" service for them that got Symantec into trouble. (IIRC, from reading some of the incident reports)

Can you name some specific examples?

IIRC several of the mis-issued SHA1 certs.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#102
post #60

Earlier quoted context omitted.

I'm fairly sure at least some of the "policy violations" that Symantec did were done exactly as a service to their large bank-or-close-enough customers. It's not that banks want to switch to a "better" SSL service, it's Symantec being a "better" service for them that got Symantec into trouble. (IIRC, from reading some of the incident reports)

Can you name some specific examples?

Symantec took one of their widely trusted root certificates and declared that it was now "off the reservation", meaning they may choose to not comply with the BRs for its leaf certificates.

I don't know if they have actively used it to issue SHA-1 certificates, but they certainly could.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#104
post #22
post #15

Earlier quoted context omitted.

I for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.

As the neighbor comment points out, EV validation is absolutely not a waste of money. I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. They don't improve security -- that is true.

Wow, that's interesting. Would you mind share numbers like percentage of A and B group?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#105
post #80

Earlier quoted context omitted.

or 3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites. I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.

>Large websites using Symantec certs start telling users Chrome is "broken" I'm having a hard time thinking of a scenario where a large website concludes it's cheaper to convince web shoppers at ecommerce sites and web visitors at news sites to switch to Firefox/IE instead of the website just switching CA vendors. If you're a website that wants to put up zero friction between buyers submitting their credit-card info…

This line of reasoning works for banks or commercial entities.

But note, it does not work for governments. They can, and will, put up a red banner instructing the user to install another browser (or in case of Firefox 52, explain how to disable updates so you can keep using NPAPI plugins).

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#106

But why is https://w3techs.com/technologies/history_overview/ssl_certif... saying Let’s Encrypt has 0.1% when https://letsencrypt.org/stats/ says 32 million Fully-Qualified Domains Active? 32 million = 0.1% 32 000 million SSL certs? = 100% ? what?

Judging by the explosive growth of IdenTrust, which cross-signs Let's Encrypt's certs, I'd guess that Let's Encrypt certs are being counted under IdenTrust.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#107
post #3

Earlier quoted context omitted.

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

I think it's likelier that Symantec will start a negative PR campaign, leading its users to yell at google to change things, perhaps calling this FUD. Whether that'll be effective is another question.

The PR campaign won't be targeting users, it'll be targeting business/site owners. A user might be annoyed that random sites stop working, but the people who operate those sites will see their traffic fall off a cliff.

The only effective solution to stop the pain will be to switch to a new cert as quickly as possible, and that only hurts Symantec, not Google

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#108
post #29
post #3

Earlier quoted context omitted.

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

users will start getting instructed by sites that they have to manually add a root certificate in order to use they site Or switch browsers. Google needs to (and will) play this so it ends up being unattractive for other browser vendors not to distrust Symantec as well.

Could actually dodgy sites then imitate bank websites, ask the same of users and then commit a MITM attack?

I'd much rather be able to say -- 'no, never manually trust a cert', instead of 'well, ok, for now yes in this one case if you're sure there's no typos in the URL... What? Yeah, the text at the top in the little bar... argh'.

I hope I'm missing something here, but even better I hope Symantec and banks get their acts together.

Post reply on HN