Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

191–200 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#191

I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? For the vast majority of users that's probably just fine, but I would have thought that there'd be a browser or extension or something that allows security-conscious power users more fine-grained control over this by now. For example,…

> I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? It doesn't. You can adjust your root certs in Firefox by going to about:preferences#advanced and clicking on certificates. But what does partial trust look like? Showing half of the HTML? An eyebrow raised emoji instead of a lock?

I wish CA management was easier to bulk-edit. Show me a table of root CAs with their data, their country of origin, etc., and allow me to filter and enable/disable all based on filters.

Full disable would shut down trust entirely, and get the warnings similar to a self-issued cert.

Reduced trust would have a "not Secure" label or something, like a plain http connection.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#192
post #55

It's a bit scary how much power do browser creators wield. Even if it's being used for good.

It will be interesting to see what happens when a Chrome user can't access his bank web site because of this, and the bank tells her to switch to Firefox/IE/Safari.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#193
post #179
post #172

Earlier quoted context omitted.

How can you know your signing software is not backdoored? How can you know you're not living in a computer simulation?

Well, I'm certain my eyes are real so I am certainly not living in a computer simulation.

How Can Our CA Roots Be Real If Our Eyes Aren't Real

https://twitter.com/officialjaden/status/329768040235413504?...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#194

Earlier quoted context omitted.

Wouldn't they just do what all browser-version-specific websites have done in the past and have an http landing page with a conditional redirect? User agent is IE6, and you progress to ie6.bankofamerica.com. User agent is Chrome/Firefox, progress to webpage with browser version warning and download link for IE6.

Maybe after their HSTS header expires. What do they do until then? Or for all the users with https bookmarks?

Well, just looking at the Bank of America example, they don't seem to use HSTS in their landing page. How widespread is HSTS? How long is the expiry period typically set for (I would guess a long time?)

Does anyone still use browser bookmarks?

Actually, just thinking about it, it might be even simpler than this. If Bank of America wanted to, couldn't they still host their redirect landing page over SSL with a valid non-Symantec certificate, and then redirect to the ie6.bankofamerica.com page which will continue to use the bad Symantec cert? If switching certs for their web infrastructure was really difficult and they didn't want to do it, they could just build a simple little front-end web server with a valid certificate to redirect people to an IE6 download page or ie6.bankofamerica.com.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#195

Earlier quoted context omitted.

They're also planning on stripping EV status from their Certs too... that's going to be fun for a lot of banks.

Oh no, of the 20 users that know about EV, 2 might send an email.

EV actually causes a different "secure" UI to display in the browser. Usually it is the name of the corporate entity that the certificate is issued for. If you don't have EV you only get a padlock.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#197

Earlier quoted context omitted.

Oh no, of the 20 users that know about EV, 2 might send an email.

EV actually causes a different "secure" UI to display in the browser. Usually it is the name of the corporate entity that the certificate is issued for. If you don't have EV you only get a padlock.

Browsers make changes like that to their UIs all the time. I highly doubt that a member of the general public would notice the difference. Heck, I doubt most developers would notice.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#198
post #24
post #17

Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…

> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

I expect the browser to look out for my interests as the user. How could the browser do that if it lets the CAs set the terms in the CAs' favor?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#199

Earlier quoted context omitted.

Oh no, of the 20 users that know about EV, 2 might send an email.

EV actually causes a different "secure" UI to display in the browser. Usually it is the name of the corporate entity that the certificate is issued for. If you don't have EV you only get a padlock.

[deleted]

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#200
post #179
post #172

Earlier quoted context omitted.

How can you know your signing software is not backdoored? How can you know you're not living in a computer simulation?

Well, I'm certain my eyes are real so I am certainly not living in a computer simulation.

"If real is what you can feel, smell, taste and see, then 'real' is simply electrical signals interpreted by your brain." -Morpheus, The Matrix

(finally, finally there's a use for that quote!)

Post reply on HN