Earlier quoted context omitted.
I'm fairly sure at least some of the "policy violations" that Symantec did were done exactly as a service to their large bank-or-close-enough customers. It's not that banks want to switch to a "better" SSL service, it's Symantec being a "better" service for them that got Symantec into trouble. (IIRC, from reading some of the incident reports)
Can you name some specific examples?
Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
101–110 of 329 posts
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#102Earlier quoted context omitted.
I'm fairly sure at least some of the "policy violations" that Symantec did were done exactly as a service to their large bank-or-close-enough customers. It's not that banks want to switch to a "better" SSL service, it's Symantec being a "better" service for them that got Symantec into trouble. (IIRC, from reading some of the incident reports)
Can you name some specific examples?
I don't know if they have actively used it to issue SHA-1 certificates, but they certainly could.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#103Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#104Earlier quoted context omitted.
I for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.
As the neighbor comment points out, EV validation is absolutely not a waste of money. I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. They don't improve security -- that is true.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#105Earlier quoted context omitted.
or 3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites. I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.
>Large websites using Symantec certs start telling users Chrome is "broken" I'm having a hard time thinking of a scenario where a large website concludes it's cheaper to convince web shoppers at ecommerce sites and web visitors at news sites to switch to Firefox/IE instead of the website just switching CA vendors. If you're a website that wants to put up zero friction between buyers submitting their credit-card info…
But note, it does not work for governments. They can, and will, put up a red banner instructing the user to install another browser (or in case of Firefox 52, explain how to disable updates so you can keep using NPAPI plugins).
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#106But why is https://w3techs.com/technologies/history_overview/ssl_certif... saying Let’s Encrypt has 0.1% when https://letsencrypt.org/stats/ says 32 million Fully-Qualified Domains Active? 32 million = 0.1% 32 000 million SSL certs? = 100% ? what?
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#107Earlier quoted context omitted.
Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…
I think it's likelier that Symantec will start a negative PR campaign, leading its users to yell at google to change things, perhaps calling this FUD. Whether that'll be effective is another question.
The only effective solution to stop the pain will be to switch to a new cert as quickly as possible, and that only hurts Symantec, not Google
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#108Earlier quoted context omitted.
Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…
users will start getting instructed by sites that they have to manually add a root certificate in order to use they site Or switch browsers. Google needs to (and will) play this so it ends up being unattractive for other browser vendors not to distrust Symantec as well.
I'd much rather be able to say -- 'no, never manually trust a cert', instead of 'well, ok, for now yes in this one case if you're sure there's no typos in the URL... What? Yeah, the text at the top in the little bar... argh'.
I hope I'm missing something here, but even better I hope Symantec and banks get their acts together.