Earlier quoted context omitted.
Banks can just switch to better SSL services...
ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…
Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
171–180 of 329 posts
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#172Earlier quoted context omitted.
It ships with your operating system, which you physically obtain from another computer (with hardware like a USB drive or via internal network).
But how to trust that this other computer has a good set of CAs?
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#173Earlier quoted context omitted.
> No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places) Why does that matter? Pretty sure you don't have to change your public key to get or renew a Let's Encrypt cert.
we spawn our servers and scale them up and down. We terminate ssl internally to our applications which are on Docker. Letsencrypt is painful on docker. I dont mind paying 40$ per year for a wildcard ssl certificate.
There is no reason for these apps to have a public cert. An app shouldn't be publicly exposed.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#174Earlier quoted context omitted.
Banks can just switch to better SSL services...
ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…
If you make such astonishingly obviously poor decisions, you deserve to fail.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#175Earlier quoted context omitted.
How is this different from StartCom except for size? Is the "too big to fail" enough of an argument here? Edit: Oh wait. Verisign and Thawte. Okay, that's some massive excrement on a collision course with the ventilation device.
StartCom were blatently lying, I don't think Symantec have stooped that low.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#176Earlier quoted context omitted.
Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…
I think it's likelier that Symantec will start a negative PR campaign, leading its users to yell at google to change things, perhaps calling this FUD. Whether that'll be effective is another question.
Google is playing with fire here. I would expect Symantec and other major business who stand to be negatively affected, especially the extremely large ones that Symantec was accommodating by skirting some of the EV rules, will immediately start pushing for regulations around this process. That's the easiest way for large companies to control this kind of thing.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#177Earlier quoted context omitted.
I for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.
EV certificates have the same level of confidentiality and integrity as DV certs, but they have different authentication - specifically, they tie the certificate to a legal entity rather than a domain name. ie. https://paypal.com-customerservice.ru vs PayPal Inc [US] | https://paypal.com I run https://certsimple.com . We sell EV certs. But you can verify the above pretty easily by checking out the EV guidelines, the…
See also the Nordea section at https://hsivonen.fi/bank-idp/ . How is a user supposed to form a mental model about multi-server org who don't use EV consistently?
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#178Earlier quoted context omitted.
i have been seriously considering comodo. Their wildcard is not priced all that bad.
According to the this survey I'm ruthlessly stealing from another comment, they have the biggest market share right now: https://w3techs.com/technologies/history_overview/ssl_certif...
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#179Earlier quoted context omitted.
But how to trust that this other computer has a good set of CAs?
How can you know your signing software is not backdoored? How can you know you're not living in a computer simulation?