Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

281–290 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#281
post #3

Earlier quoted context omitted.

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

Maybe, but in the meantime I can't imagine a scenario where such a direct financial threat to a business isn't vigorously defended by Symantec. I'm not a lawyer, but certainly they must be working to determine if they have a legal basis for seeking an injunction against Google. They could even be building some sort of legal theory based on tortious business interference, contending that Google is doing irreparable ha…

That seems unlikely if Symantec have indeed violated the CA/B Forum Baseline Requirements that they already agreed to.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#282
post #134

Earlier quoted context omitted.

Crazy! A third of SYMC's revenue might be going POOF! and the market is just shrugging?

They'll all be caught by surprise and lose their shirts when Symantec releases their financials next quarter and the stock tanks. The market is full of ignorant people.

Just remember that the market can afford to be wrong longer than you can afford to bet against it.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#283
post #276

Why not immediately begin treating these connections as plain HTTP? Don't show the padlock or "Secure". Don't fail the connection, so people will still be able to use the site, but don't present it as secure. This would be a stronger action than treating EV certs as non-EV, which only a few geeks will notice. Or reducing the maximum age of certificates.

And teach your grandpa it's ok if his bank's website no longer displays that green address bar?

Making your grandpa think everything is right with the bank defeats the whole point of what Google is trying to do.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#286
post #35

Earlier quoted context omitted.

Your pricing is very reasonable and I've just placed your website at the top of my to-do list tomorrow morning, thanks for posting.

Thanks! We're actually about the middle of the road price wise, our main thing is tech: the EV process can be pretty painful, our role is to speed it it up and make it easier. We start checking against government directories in 63 countries prior to payment, use webcrypto in supported browsers to quickly generate CSRs, make instant-paste openssl / windows scripts to make an ECC or RSA keypair quickly if you prefer to…

Your mobile page doesn't show any pricing, and the FAQ redirects to the front page.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#287
post #202
post #127

Earlier quoted context omitted.

Haven't they been hacked more than once?

One of Comodo's registration authorities was breached, but not Comodo themselves. Comodo were able to detect the breach and cut off the compromised RA because they were monitoring what their RAs were doing. Symantec, on the other hand, didn't know that their RAs were mis-validating certificates until I noticed and told them. (Registration authorities are third parties that perform certificate validation on behalf of…

[deleted]

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#288
post #202
post #127

Earlier quoted context omitted.

Haven't they been hacked more than once?

One of Comodo's registration authorities was breached, but not Comodo themselves. Comodo were able to detect the breach and cut off the compromised RA because they were monitoring what their RAs were doing. Symantec, on the other hand, didn't know that their RAs were mis-validating certificates until I noticed and told them. (Registration authorities are third parties that perform certificate validation on behalf of…

It wasn't one but three authorities which have been breached.

And maybe you should disclose that you are a Comodo reseller.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#289

Earlier quoted context omitted.

Browsers make changes like that to their UIs all the time. I highly doubt that a member of the general public would notice the difference. Heck, I doubt most developers would notice.

I agree, because I experienced it just now. I'm on Chrome 57 and just realized that Chrome certificate details UI seems to have changed sometime recently. I remember I could earlier click on the padlock or "Secure" text, click More (or something) on the popup and it would display certificate details in developer tools (which is itself weird, but atleast it was available for end users). Now, it doesn't give any direct…

You just made me look, and what I saw made me sad. Even more than I already was. :(

"Let's remove this thing that is super useful while your stated goal could just as easily be reached while keeping the original functionality." Bill Hicks was so incredibly right about marketing.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#290
post #242

Earlier quoted context omitted.

The issue has gotten plenty of public discussion (from Google, Mozilla, and others) on Mozilla's dev-security-policy mailing list: https://groups.google.com/forum/?fromgroups=#!forum/mozilla....

The main thread is https://groups.google.com/forum/?fromgroups=#!topic/mozilla.... , and it contains some nuggets like this: So after reading this, the following auditors aren't trusted by Symantec anymore: - E&Y Korea - E&Y Brazil The following isn't trusted by Mozilla anymore: - E&Y Hong Kong This seems to be a worrying trend to me. Kurt

I was curious if E&Y was Ernst & Young, and indeed it is, apparently they go by the name of EY now.

I found this attached PDF interesting as well: https://bug1334377.bmoattachments.org/attachment.cgi?id=8831...

Post reply on HN