Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

141–150 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#141

Earlier quoted context omitted.

The max time also starts at 33 months w/ Chrome 59 so thankfully they're giving plenty of time to either resolve the situation or have people switch CAs.

Not really. By the end of the year with their schedule Chrome 64 will be out with 9 month validity. Then who knows after that. So it is at the most 18 months.

You're right. I didn't look into the Chrome release schedule so I just assumed they followed the max validity deprecation schedule. My mistake.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#142

Earlier quoted context omitted.

Can you name some specific examples?

Symantec took one of their widely trusted root certificates and declared that it was now "off the reservation", meaning they may choose to not comply with the BRs for its leaf certificates. I don't know if they have actively used it to issue SHA-1 certificates, but they certainly could.

But how or why was this done as a favour for their banking customers?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#143
post #3
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

It is workable. This gets brought up every time we have an issue like this. The problem is that existing CA's keep fucking up. But the system is clearly working: bad CA's get excluded.

I think the likely result here is more widespread adoption of LE. The point is that CA's shouldn't be businesses.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#144

Symantec being well... Symantec, I'd expecting them to lawyer up in order to delay, or outright block this. They're big enough to afford the higher end law firms likely needed too. :(

They're not bigger than Google. And it's Google's browser and the open source Chromium project, so I'm having a hard time seeing how Symantec is going to get a judge to say anything along the lines of "I forbid any and all members of the Chromium project to commit anything to the codebase that would no longer treat Symantec issued certificates as before". Especially considering since plenty aren't under US jurisdiction nor necessarily employed by Google.

Then they'd also have to strong arm Mozilla, Apple and Microsoft since they're rather likely to act too and at least the latter two don't disclose such changes until they've made them.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#145
post #41

Earlier quoted context omitted.

They're also planning on stripping EV status from their Certs too... that's going to be fun for a lot of banks.

Banks can just switch to better SSL services...

Somebody needs to tell Bank of America. They're still presenting a Symantec EV cert.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#146
post #52

Earlier quoted context omitted.

> No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places) Why does that matter? Pretty sure you don't have to change your public key to get or renew a Let's Encrypt cert.

we spawn our servers and scale them up and down. We terminate ssl internally to our applications which are on Docker. Letsencrypt is painful on docker. I dont mind paying 40$ per year for a wildcard ssl certificate.

If you use the DNS auth, its actually not bad: you can securely issue the certs on a different machine and just copy the PEM files to the right place. I used this with Route 53's API and it works quite well and is (in my opinion) superior to having to place files.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#147
post #123
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

Am I the only one worried about LetsEncrypt becoming a monopoly? This move from Google is, indirectly, a huge service for them.

Arguably, they could just adopt LE technology wholesale. Shrinking cert lifetimes is compatible LE's already short cert lifetimes.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#148

TLDR: Google has lost trust in Symantec's ability to properly validate certificates they issue. Chrome has a Root Certificate Policy that expects a CA to perform in a manner commensurate with the trust being placed in them and the Google team appears to see evidence that they are not living up to the standard laid out. They propose a gradual distrust of existing certificates by reducing the 'maximum age' of the certi…

This is a good summary, but I'd clarify it by saying that Google isn't being subjective about Symantec's process failures. The CA industry self-regulates. Its regulatory organization is the CA/B Forum, and their principal regulation is the Baseline Requirements (the BRs). Google claims Symantec violated multiple BRs. If you want to dig a little deeper, here's the last version of the BRs: https://cabforum.org/wp-conte…

Have they published anywhere the violations?

Normally browser makers publish openly evidence of mis-issued certificates, together with having the discussion with the vendor in the public.

It's sad that this announcement from Google seems to basically be saying "we had a closed door dispute with Symantec, and now don't trust them".

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#149

TL;DR Google prefers to override what the standards say about validity of certicates instead of what would be the logical thing: stop trusting Symantec root Certs. A dangerous precedent.

Google is divesting trust from Symantec but is doing it in a way that avoids hurting end-users and badly breaking the internet. They explicitly state why they don't just want to revoke it in one go and they have really decent arguments. What are yours?

Aside from that, to the best of my knowledge the CA/B forum doesn't set forth any rules that require the immediate and complete removal of trust of a CA that is found to be in violation of the guidelines. I also don't see how they could, the best they could do is put out some form of recommendation but it's up to the parties that actually include the CAs to decide how they get removed, which is normally stipulated in the rules for inclusion in a Root Certificate bundle.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#150
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

How is this different from StartCom except for size? Is the "too big to fail" enough of an argument here? Edit: Oh wait. Verisign and Thawte. Okay, that's some massive excrement on a collision course with the ventilation device.

StartCom were blatently lying, I don't think Symantec have stooped that low.
Post reply on HN