Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

121–130 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#121

I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? For the vast majority of users that's probably just fine, but I would have thought that there'd be a browser or extension or something that allows security-conscious power users more fine-grained control over this by now. For example,…

> Or I could subscribe to feeds from other entities I trust, like the EFF. How would you validate that the EFF's feed is actually from the EFF? Assuming we're using existing SSL infrastructure, the browser would first need to trust the CA used by the EFF, which means we need an initial set of trusted CAs.

> which means we need an initial set of trusted CAs.

How would you validate that the initial set of trusted CA roots is actually from those CAs?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#122
post #15

Earlier quoted context omitted.

Perhaps it's neat for you, I just found out that our newly issued EV certificate status is being revoked in the next build of Chrome, so our expensive EV certificates may as well be $5 StartSSL certificates. I imagine that there will be a lot of angry customers asking for refunds from Symantec/Verisign for certificates already issued which no longer conform to the offered product.

I for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.

What? Of course they improve security. They reduce the risk the user has accidentally navigated to a squatted typo-domain registered by an attacker (or the correct domain, but the registration somehow accidentally expired and was reregistered by an attacker)

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#123
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

Am I the only one worried about LetsEncrypt becoming a monopoly? This move from Google is, indirectly, a huge service for them.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#124
If anyone here hasn't realised, Symantec bought Verisign back in 2010 - who own many brand names, like GeoTrust, Equifax, Thawte etc. You can see a list of their roots certs here: https://chromium.googlesource.com/chromium/src/+/master/net/...

In case you missed it at the bottom:

> From Mozilla Firefox’s Telemetry, we know that Symantec issued certificates are responsible for 42% of certificate validations

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#125
post #24
post #17

Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…

> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

The standards group in question is unfortunately impotent. Two totally reliable voting blocs: the browsers and the CAs. There are more CAs than browsers, so the result of every vote is in the favour of the CAs.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#126

Earlier quoted context omitted.

Can you name some specific examples?

Symantec took one of their widely trusted root certificates and declared that it was now "off the reservation", meaning they may choose to not comply with the BRs for its leaf certificates. I don't know if they have actively used it to issue SHA-1 certificates, but they certainly could.

You will notice that was also their SGC root, and one of the oldest roots that browsers trusted.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#127

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

Well, Comodo's had an okay track-record, if I recall correctly. But I also don't recall them being cheap.

Haven't they been hacked more than once?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#128
post #29

Earlier quoted context omitted.

users will start getting instructed by sites that they have to manually add a root certificate in order to use they site Or switch browsers. Google needs to (and will) play this so it ends up being unattractive for other browser vendors not to distrust Symantec as well.

Could actually dodgy sites then imitate bank websites, ask the same of users and then commit a MITM attack? I'd much rather be able to say -- 'no, never manually trust a cert', instead of 'well, ok, for now yes in this one case if you're sure there's no typos in the URL... What? Yeah, the text at the top in the little bar... argh'. I hope I'm missing something here, but even better I hope Symantec and banks get their…

Could actually dodgy sites then imitate bank websites, ask the same of users and then commit a MITM attack?

Technically, certificate pinning etc can prevent this, but in practice, yes, this is a possible attack vector.

But it has little to do with CA validation. If the user understands how to verify the domain and security of the connection the attack doesn't work, and if he doesn't, the Google vs Symantec situation makes no difference either.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#129

TLDR: Google has lost trust in Symantec's ability to properly validate certificates they issue. Chrome has a Root Certificate Policy that expects a CA to perform in a manner commensurate with the trust being placed in them and the Google team appears to see evidence that they are not living up to the standard laid out. They propose a gradual distrust of existing certificates by reducing the 'maximum age' of the certi…

This is a good summary, but I'd clarify it by saying that Google isn't being subjective about Symantec's process failures. The CA industry self-regulates. Its regulatory organization is the CA/B Forum, and their principal regulation is the Baseline Requirements (the BRs). Google claims Symantec violated multiple BRs.

If you want to dig a little deeper, here's the last version of the BRs:

https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#130
post #114
post #105

Earlier quoted context omitted.

This line of reasoning works for banks or commercial entities. But note, it does not work for governments. They can, and will, put up a red banner instructing the user to install another browser (or in case of Firefox 52, explain how to disable updates so you can keep using NPAPI plugins).

Interesting point. I spot checked CAs for some of the most popular USA government websites. irs.gov (Internal Revenue Service): Entrust CA va.gov (Veterans Affairs) : Symantec CA So if Symantec is the CA for a critical mass of government websites that won't abandon them, Google Chrome could lose this battle. Without looking at traffic data (e.g Alexa), my intuition says the vast majority of web traffic is not governm…

I believe it is actually a matter of political campaigning in South Korea to get rid of ancient IE ActiveX requirements for government websites.
Post reply on HN