Earlier quoted context omitted.
Obviously they get another cert, but only serve it to chrome users via SSL handshake fingerprinting, and serve the Symantec cert to everybody else...
I can't tell if you're joking. Just in case you're not, if they went through all the trouble to get another cert for Chrome, why wouldn't they just use it for everyone?
Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
301–310 of 329 posts
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#302Earlier quoted context omitted.
Browsers make changes like that to their UIs all the time. I highly doubt that a member of the general public would notice the difference. Heck, I doubt most developers would notice.
I agree, because I experienced it just now. I'm on Chrome 57 and just realized that Chrome certificate details UI seems to have changed sometime recently. I remember I could earlier click on the padlock or "Secure" text, click More (or something) on the popup and it would display certificate details in developer tools (which is itself weird, but atleast it was available for end users). Now, it doesn't give any direct…
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#303The whole security model of the web is quite centralized maybe we need something more distributed? What if you had strong hashing on content, distributed webservers and distributed content?
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#304Earlier quoted context omitted.
Maybe after their HSTS header expires. What do they do until then? Or for all the users with https bookmarks?
Well, just looking at the Bank of America example, they don't seem to use HSTS in their landing page. How widespread is HSTS? How long is the expiry period typically set for (I would guess a long time?) Does anyone still use browser bookmarks? Actually, just thinking about it, it might be even simpler than this. If Bank of America wanted to, couldn't they still host their redirect landing page over SSL with a valid n…
This made me cry a little. But on a more serious note, every existing link on the Web is essentially a bookmark, so I don't think we can ignore that when discussing impact. (Though I'm betting all incoming requests could be rerouted more easily than telling your customers to (and how to) install a cert...)
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#305Here's Symantec's press release:
Google’s statements about our issuance practices and the scope of our past mis-issuances are exaggerated and misleading. For example, Google’s claim that we have mis-issued 30,000 SSL/TLS certificates is not true. In the event Google is referring to, 127 certificates – not 30,000 – were identified as mis-issued, and they resulted in no consumer harm. We have taken extensive remediation measures to correct this situation, immediately terminated the involved partner’s appointment as a registration authority (RA), and in a move to strengthen the trust of Symantec-issued SSL/TLS certificates, announced the discontinuation of our RA program. This control enhancement is an important move that other public certificate authorities (CAs) have not yet followed.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#306Earlier quoted context omitted.
This is not accurate. To pass, a ballot must receive a 2/3 majority from CAs AND a 1/2 majority from browsers. While there have been some contentious votes along CA-browser lines, you can see from the ballot history that most ballots have passed and thus had support from both browsers and CAs: https://cabforum.org/ballots/
Oh let me guess how this goes: > Ballot 161 – Notification of incorrect issuance > In the event that a CA issues a certificate in violation of these requirements, the CA SHALL publicly disclose a report within one week of becoming aware of the violation. A link to the report SHALL simultaneously be sent to incidents@cabforum.org. > From the CAs, there were 0 YES votes, 14 NO votes and 5 Abstentions > From the Browser…
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#307I was curious if this would affect my Symantec issued certs... according to my date math: Chrome 59 (Apr 13, 2017) +1023 days: 2020-01-31 Chrome 60 (May 25th, 2017) +837 days: 2019-09-09 Chrome 61 (Jul 20th, 2017) +651 days: 2019-05-02 Chrome 62 (Aug 31st, 2017) +465 days: 2018-12-09 Chrome 63 (Oct 12th, 2017) +279 days: 2018-07-18
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#308"...pour encourager les autres"
In English please?
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#309Earlier quoted context omitted.
As someone who just renewed a Symantec EV cert (for a pretty penny), this would super piss me off. The steps Google has laid out seem proportionate to me. It clearly gets the message across without unduly burdening 3rd parties like me. And it has nudged me to look at other CAs. Unfortunately the first good option I've looked at--Digicert--has also been publicly rapped on the knuckles by Ryan Sleevi this month.
Pissing off Symantec customers is a necessary evil in this case. It's a sign that the strategy is working.
Imagine if Chrome started reporting all Apple and Microsoft domains as insecure, with no warning. That's straying into very deep waters.
To be clear: I support Google's action against Symantec, and it is causing me to look at other CAs. But I need time to make an orderly change.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#310Earlier quoted context omitted.
They'll all be caught by surprise and lose their shirts when Symantec releases their financials next quarter and the stock tanks. The market is full of ignorant people.
Just remember that the market can afford to be wrong longer than you can afford to bet against it.