Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

171–180 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#171
post #50
post #41

Earlier quoted context omitted.

Banks can just switch to better SSL services...

ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…

suddenly everyone gets hauled into a change control board meeting to chance a cert on an F5

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#172
post #158
post #133

Earlier quoted context omitted.

It ships with your operating system, which you physically obtain from another computer (with hardware like a USB drive or via internal network).

But how to trust that this other computer has a good set of CAs?

How can you know your signing software is not backdoored? How can you know you're not living in a computer simulation?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#173
post #52

Earlier quoted context omitted.

> No we cannot use LetsEncrypt for convenience reasons (we bake our certificate pub key in many places) Why does that matter? Pretty sure you don't have to change your public key to get or renew a Let's Encrypt cert.

we spawn our servers and scale them up and down. We terminate ssl internally to our applications which are on Docker. Letsencrypt is painful on docker. I dont mind paying 40$ per year for a wildcard ssl certificate.

Use self signed certificate with your own CA.

There is no reason for these apps to have a public cert. An app shouldn't be publicly exposed.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#174
post #50
post #41

Earlier quoted context omitted.

Banks can just switch to better SSL services...

ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…

Well, you guys here love capitalism, and this is capitalism.

If you make such astonishingly obviously poor decisions, you deserve to fail.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#175

Earlier quoted context omitted.

How is this different from StartCom except for size? Is the "too big to fail" enough of an argument here? Edit: Oh wait. Verisign and Thawte. Okay, that's some massive excrement on a collision course with the ventilation device.

StartCom were blatently lying, I don't think Symantec have stooped that low.

Hard to say which is worse, the intentional lying or the fact that Symantec has repeatedly violated the BR's and root store policies despite the appearance of best efforts not to.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#176
post #3

Earlier quoted context omitted.

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

I think it's likelier that Symantec will start a negative PR campaign, leading its users to yell at google to change things, perhaps calling this FUD. Whether that'll be effective is another question.

Yes. You can't just jeopardize a substantial portion of a large company's revenue stream like this and not expect retaliation. Guaranteed that unless the executive team steps in to reverse this, Google has made itself a few powerful enemies.

Google is playing with fire here. I would expect Symantec and other major business who stand to be negatively affected, especially the extremely large ones that Symantec was accommodating by skirting some of the EV rules, will immediately start pushing for regulations around this process. That's the easiest way for large companies to control this kind of thing.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#177
post #26
post #15

Earlier quoted context omitted.

I for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.

EV certificates have the same level of confidentiality and integrity as DV certs, but they have different authentication - specifically, they tie the certificate to a legal entity rather than a domain name. ie. https://paypal.com-customerservice.ru vs PayPal Inc [US] | https://paypal.com I run https://certsimple.com . We sell EV certs. But you can verify the above pretty easily by checking out the EV guidelines, the…

If a site with an EV cert is being spoofed using a similar-looking domain name and a DV cert, how realistically is the user going to remember that the real site is supposed to have an EV cert? (Besides just maybe remembering it for Paypal in particular.)

See also the Nordea section at https://hsivonen.fi/bank-idp/ . How is a user supposed to form a mental model about multi-server org who don't use EV consistently?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#178

Earlier quoted context omitted.

i have been seriously considering comodo. Their wildcard is not priced all that bad.

According to the this survey I'm ruthlessly stealing from another comment, they have the biggest market share right now: https://w3techs.com/technologies/history_overview/ssl_certif...

That might be because they're the CA underlying Cloudflare's automated SSL issuance - at least for free tier customers.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#179
post #172
post #158

Earlier quoted context omitted.

But how to trust that this other computer has a good set of CAs?

How can you know your signing software is not backdoored? How can you know you're not living in a computer simulation?

Well, I'm certain my eyes are real so I am certainly not living in a computer simulation.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#180
We need a service to check if your certs could be flagged as bad. Especially since this spans so many brands (Symantec, Equifax, VeriSign, GeoTrust, Thawte, etc). Something like, plug in the domain name, and it'll tell you if you need to update the cert.
Post reply on HN