Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

291–300 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#291
post #228

Earlier quoted context omitted.

Things that go to vote in the CAB Forum are often split pretty exactly down CA v. browser lines, and the CA outnumber the browsers and hence typically win. That said, the power of the browser vendors as those who maintain the trust stores is obviously there.

This is not accurate. To pass, a ballot must receive a 2/3 majority from CAs AND a 1/2 majority from browsers. While there have been some contentious votes along CA-browser lines, you can see from the ballot history that most ballots have passed and thus had support from both browsers and CAs: https://cabforum.org/ballots/

Oh let me guess how this goes:

> Ballot 161 – Notification of incorrect issuance

> In the event that a CA issues a certificate in violation of these requirements, the CA SHALL publicly disclose a report within one week of becoming aware of the violation. A link to the report SHALL simultaneously be sent to incidents@cabforum.org.

> From the CAs, there were 0 YES votes, 14 NO votes and 5 Abstentions

> From the Browsers, there were 3 YES votes, 0 NO votes and 0 Abstentions.

sigh

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#292
post #280
post #255

Earlier quoted context omitted.

I could go for an eyebrow-raised emoji in some cases. Self-signed certs for instance, or any root cert that the browser picks up from the OS.

Is there an eavesdropper emoji?

U+1F575 SLEUTH OR SPY

Useless. On my computer it looks like Firefox is using a font that has a sleuth with a magnifying glass and a hat, while Emacs uses a font that has a silhouette of a guy wearing a trenchcoat.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#293
post #206

Earlier quoted context omitted.

This is a good summary, but I'd clarify it by saying that Google isn't being subjective about Symantec's process failures. The CA industry self-regulates. Its regulatory organization is the CA/B Forum, and their principal regulation is the Baseline Requirements (the BRs). Google claims Symantec violated multiple BRs. If you want to dig a little deeper, here's the last version of the BRs: https://cabforum.org/wp-conte…

Small correction: the CA industry doesn't self-regulate. Both browsers and CAs participate in the CA/Browser Forum and my (admittedly outsider) impression is that browsers almost always have the upper hand.

But if I understand correctly, this decision was Google's entirely?

If that is the case then it doesn't matter much what forum thinks about Symantec. Buying a certificate which is not supported by a major browser vendor would be... eccentric, so my guess is this will be a major blow for Symantec certificate business.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#294
post #167

Earlier quoted context omitted.

Banks and companies like First Data were the (sole?) source of exception requests for SHA-1 issuance past the date it was prohibited. Given the G1 root they pulled has an intermediary called "Symantec Trust Services Private SHA1 Root CA", I can make some guesses...

The exception process used by payment processors such as First Data were for SHA-1 certificates chaining to a root that was still publicly-trusted. They couldn't use an off-reservation root because their client devices didn't trust them. The roots that Symantec took off-reservation are regularly issuing SHA-1 certificates to anyone whose check clears. Got $1,699 to spare? https://www.thesslstore.com/symantec/secure-s…

Indeed, I was just speculating that more banks and payment processors might take advantage of the off-reservation root if it was possible, given the type of companies that publicly showed they needed one.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#295

Earlier quoted context omitted.

EV actually causes a different "secure" UI to display in the browser. Usually it is the name of the corporate entity that the certificate is issued for. If you don't have EV you only get a padlock.

Oh, I know. But name me a non-IT professional that knows the difference, or would care that their bank has "secure" and not "Bank of America LLC". I think there are groups of smart PKI/UI people discussing how better to design security warnings at various levels of EV/HTTPS/Partial HTTPS/HTTP.

> name me a non-IT professional that knows the difference, or would care that their bank has "secure"

It has the secure padlock as an image on the page! And a green check mark!

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#296
post #87

Earlier quoted context omitted.

How will these websites communicate #3? Through the blocked website?

Obviously they get another cert, but only serve it to chrome users via SSL handshake fingerprinting, and serve the Symantec cert to everybody else...

I can't tell if you're joking.

Just in case you're not, if they went through all the trouble to get another cert for Chrome, why wouldn't they just use it for everyone?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#298
post #202

Earlier quoted context omitted.

One of Comodo's registration authorities was breached, but not Comodo themselves. Comodo were able to detect the breach and cut off the compromised RA because they were monitoring what their RAs were doing. Symantec, on the other hand, didn't know that their RAs were mis-validating certificates until I noticed and told them. (Registration authorities are third parties that perform certificate validation on behalf of…

It wasn't one but three authorities which have been breached. And maybe you should disclose that you are a Comodo reseller.

I used to be a Symantec reseller too before I realized how bad they were. I only do business with CAs which I actually believe are good.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#300
post #267
post #225

Earlier quoted context omitted.

> I may be being a bit dense, but if your client device contains a root that goes off-reservation, how does it ever receive a revocation notice? Doesn't everything that chains to that root via a valid chain still get trusted? Yes, if a client isn't receiving root store updates it will continue to trust certificates chaining to the off-reservation root. This is why taking previously-trusted roots off-reservation is ba…

Wow, the two of those combined with embedded systems with extended lifecycles seem like a recipe for disaster.

It really is :-(
Post reply on HN