Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

181–190 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#181
post #9
post #3

Earlier quoted context omitted.

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

Remember google has chrome AND android. I think they're big enough to win this battle if it comes down to that. Symantec is at the clear disadvantage.

>Symantec is at the clear disadvantage.

I'm not sure how they are at a disadvantage if they have supplied 30% of in-use certificates, and are responsible for 42% of all validations.

While I don't condone Symantec's behaviour, I think google is being a bit hypocritical here. Have you ever tried reporting gmail spammers to google?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#182
post #9

Earlier quoted context omitted.

Remember google has chrome AND android. I think they're big enough to win this battle if it comes down to that. Symantec is at the clear disadvantage.

>Symantec is at the clear disadvantage. I'm not sure how they are at a disadvantage if they have supplied 30% of in-use certificates, and are responsible for 42% of all validations. While I don't condone Symantec's behaviour, I think google is being a bit hypocritical here. Have you ever tried reporting gmail spammers to google?

Sans maybe spear phishers, spam campaigns aren't generally ran by oppressive governments. MiTM certs with bogus certs absolutely are, and could result in jail / death.

EFF ftw!

https://ssd.eff.org/

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#183
post #3
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

> brought to bear

I think the idiom you want is "brought to heel".

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#184
post #123
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

Am I the only one worried about LetsEncrypt becoming a monopoly? This move from Google is, indirectly, a huge service for them.

I'd be quite happy if LetsEncrypt becomes a significant monopoly - they're following much better practices than many other CAs, they run on open source software and are generally operated in a much more transparent way than other CAs. By using stuff like Certificate Transparency Let's Encrypt makes it so their issuances are publicly auditable - much more than many other CAs are doing these days.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#185
Not much focus in the comments has been put on the 9-month certificate validity, but it seems like that is going to be almost as big a punishment for Symantec as the deprecation. Because dealing with SSL is so painful for some large corporates, being told that you have to go from a 3 year renewal schedule to a 9 month one would be enough to cause many to go looking elsewhere.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#186
post #87

Earlier quoted context omitted.

How will these websites communicate #3? Through the blocked website?

Wouldn't they just do what all browser-version-specific websites have done in the past and have an http landing page with a conditional redirect? User agent is IE6, and you progress to ie6.bankofamerica.com. User agent is Chrome/Firefox, progress to webpage with browser version warning and download link for IE6.

Maybe after their HSTS header expires. What do they do until then? Or for all the users with https bookmarks?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#187

It amazes me how often Symantec is in the news about the same subject, yet they seem to be incapable of learning a lesson from it.

As they say "It is difficult to get a man to understand something, when his salary depends upon his not understanding it."

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#188
post #87

Earlier quoted context omitted.

or 3) Large websites using Symantec certs start telling users Chrome is "broken" and we find out if users will switch browsers, not care about the security, and/or complain to the sites. I definitely find any variation of #3 to be more likely than #2. I see it as a battle between #1 and #3.

How will these websites communicate #3? Through the blocked website?

Obviously they get another cert, but only serve it to chrome users via SSL handshake fingerprinting, and serve the Symantec cert to everybody else...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#189
Good. The security of certificate system is dependent on an incentive model where misbehavior is punished with revocation. It is important not just because we shouldn't give individual authorities trust after they have demonstrated themselves untrustworthy (although that is an important factor), but also as a punitive measure to disincentive misbehavior.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#190

TLDR: Google has lost trust in Symantec's ability to properly validate certificates they issue. Chrome has a Root Certificate Policy that expects a CA to perform in a manner commensurate with the trust being placed in them and the Google team appears to see evidence that they are not living up to the standard laid out. They propose a gradual distrust of existing certificates by reducing the 'maximum age' of the certi…

They're also planning on stripping EV status from their Certs too... that's going to be fun for a lot of banks.

Oh no, of the 20 users that know about EV, 2 might send an email.
Post reply on HN