Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

161–170 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#161
post #8
post #5

I'd be very surprised if Symantec doesn't have some backroom deal with intelligence agencies, and not just in the U.S. either, especially since they've acquired BlueCoat - a "security company" known for selling surveillance tools to authoritarian regimes - and after they made the BlueCoat CEO the CEO of Symantec.

Prior to the Symantec aquisition, VeriSign used to pitch just this thing as a product. AFAIK the usage was limited to DoD and a few mundane things. The IC wasn't interested because it was easier for them to just steal certificates or work around TLS completely.

Interesting that it would be "so much easier" for the U.S. intelligence community to steal most certificates or work around TLS, when countries like Thailand, which have much fewer resources, prefer to get Microsoft to install their own root certificate for them in Windows. Perhaps this is what the IC meant as well, when it said there are other easier ways? Why bother with Verisign's solution, when they could have their own root certs in Windows?

The CA system is such an untrustworthy mess.

http://www.theverge.com/2017/1/25/14381174/microsoft-thailan...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#162
post #77

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

I have heard lots of good things about Digicert, FWIW. No personal experience as my use case can be covered by LetsEncrypt.

What about Globalsign?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#163

Earlier quoted context omitted.

Well, Comodo's had an okay track-record, if I recall correctly. But I also don't recall them being cheap.

i have been seriously considering comodo. Their wildcard is not priced all that bad.

Comodo, as in the Comodo which tried to trademark "Let's Encrypt" last year? https://arstechnica.com/tech-policy/2016/06/800-pound-comodo...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#164

Symantec being well... Symantec, I'd expecting them to lawyer up in order to delay, or outright block this. They're big enough to afford the higher end law firms likely needed too. :(

They're not bigger than Google. And it's Google's browser and the open source Chromium project, so I'm having a hard time seeing how Symantec is going to get a judge to say anything along the lines of "I forbid any and all members of the Chromium project to commit anything to the codebase that would no longer treat Symantec issued certificates as before". Especially considering since plenty aren't under US jurisdicti…

Sure, it'd probably be an uphill battle.

But, Symantec has generally shown little/no morals in past times when it comes to attempting to protect their business interests. Not really seeing why this would be different. :/

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#165
post #87

Earlier quoted context omitted.

or 3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites. I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.

How will these websites communicate #3? Through the blocked website?

Wouldn't they just do what all browser-version-specific websites have done in the past and have an http landing page with a conditional redirect? User agent is IE6, and you progress to ie6.bankofamerica.com. User agent is Chrome/Firefox, progress to webpage with browser version warning and download link for IE6.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#166
post #117

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

Also wondering this, as I'm about to buy a new cert.

I switched to DIGICERT when Verisign started buying everyone up (then Symantec bought them). I haven't looked back...except for dev boxes where I can get away with Let's Encrypt.

For business I highly recommend DIGICERT. They are an independent company.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#167

Earlier quoted context omitted.

But how or why was this done as a favour for their banking customers?

Banks and companies like First Data were the (sole?) source of exception requests for SHA-1 issuance past the date it was prohibited. Given the G1 root they pulled has an intermediary called "Symantec Trust Services Private SHA1 Root CA", I can make some guesses...

The exception process used by payment processors such as First Data were for SHA-1 certificates chaining to a root that was still publicly-trusted. They couldn't use an off-reservation root because their client devices didn't trust them.

The roots that Symantec took off-reservation are regularly issuing SHA-1 certificates to anyone whose check clears. Got $1,699 to spare? https://www.thesslstore.com/symantec/secure-site-pro-sha1-pr...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#168

I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? For the vast majority of users that's probably just fine, but I would have thought that there'd be a browser or extension or something that allows security-conscious power users more fine-grained control over this by now. For example,…

You can always disable everything except for LE.

It's not WoT because WoT is supposed to help you know of unknown people are secure (say LE and FSF trusts ABC, it probably means that ABC is reliable), which doesn't work at all

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#169
post #89
post #78

Earlier quoted context omitted.

If I'm reading the post right, it's stricter than that: > ...distrusting certificates whose validity period (the difference of notBefore to notAfter) exceeds the specified maximum. I.e., a certificate valid from 1/2015..1/2019 is distrusted as of Chrome 59. And the more lax restrictions only apply to certificates that have already been issued. Any one issued after Chrome 61 are held to the highest (9 mo) limit. > In…

I agree with the newly issued certs. The other, that's going to be painful, and a mess to figure out, if you are right.. and that's quite possible that you are. UGH. EDIT: Update, I'm not sure you are correct, I just downloaded the latest dev release (Version 59.0.3047.0 (Official Build) dev (64-bit)) and it accepts a rapidssl issued(symantec owned) cert valid for 1187 days, which would exceed the 1023 days. It's als…

> It's also possible it just hasn't made it into the release yet,

The proposal was just made, so you shouldn't expect it to be reflected in code just yet.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#170
post #77

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

I have heard lots of good things about Digicert, FWIW. No personal experience as my use case can be covered by LetsEncrypt.

Seconding Digicert. They're expensive, but the most solid and trustworthy option when it comes to "old school" cert providers. EV, Wildcard, code signing.
Post reply on HN