Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

301–310 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#301

Earlier quoted context omitted.

Obviously they get another cert, but only serve it to chrome users via SSL handshake fingerprinting, and serve the Symantec cert to everybody else...

I can't tell if you're joking. Just in case you're not, if they went through all the trouble to get another cert for Chrome, why wouldn't they just use it for everyone?

I suspect it was a joke, but you raise a very important question. Unfortunately, some clients (likely embedded devices) trust only Symantec roots, since that's the CA the website was using at the time the developer slapped together their code.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#302

Earlier quoted context omitted.

Browsers make changes like that to their UIs all the time. I highly doubt that a member of the general public would notice the difference. Heck, I doubt most developers would notice.

I agree, because I experienced it just now. I'm on Chrome 57 and just realized that Chrome certificate details UI seems to have changed sometime recently. I remember I could earlier click on the padlock or "Secure" text, click More (or something) on the popup and it would display certificate details in developer tools (which is itself weird, but atleast it was available for end users). Now, it doesn't give any direct…

I noticed that a while ago. I thought I was just doing something wrong.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#303
Why trust central CA who say security charge for it but do not implement it? Why not instead use a distributed security model such as LetsEncrypt and Blockchain?

The whole security model of the web is quite centralized maybe we need something more distributed? What if you had strong hashing on content, distributed webservers and distributed content?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#304

Earlier quoted context omitted.

Maybe after their HSTS header expires. What do they do until then? Or for all the users with https bookmarks?

Well, just looking at the Bank of America example, they don't seem to use HSTS in their landing page. How widespread is HSTS? How long is the expiry period typically set for (I would guess a long time?) Does anyone still use browser bookmarks? Actually, just thinking about it, it might be even simpler than this. If Bank of America wanted to, couldn't they still host their redirect landing page over SSL with a valid n…

> Does anyone still use browser bookmarks?

This made me cry a little. But on a more serious note, every existing link on the Web is essentially a bookmark, so I don't think we can ignore that when discussing impact. (Though I'm betting all incoming requests could be rerouted more easily than telling your customers to (and how to) install a cert...)

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#305
Symantec thinks Google is being inflammatory. Symantec fired the people who made the test cert a couple of years ago.

Here's Symantec's press release:

Google’s statements about our issuance practices and the scope of our past mis-issuances are exaggerated and misleading. For example, Google’s claim that we have mis-issued 30,000 SSL/TLS certificates is not true. In the event Google is referring to, 127 certificates – not 30,000 – were identified as mis-issued, and they resulted in no consumer harm. We have taken extensive remediation measures to correct this situation, immediately terminated the involved partner’s appointment as a registration authority (RA), and in a move to strengthen the trust of Symantec-issued SSL/TLS certificates, announced the discontinuation of our RA program. This control enhancement is an important move that other public certificate authorities (CAs) have not yet followed.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#306
post #291
post #228

Earlier quoted context omitted.

This is not accurate. To pass, a ballot must receive a 2/3 majority from CAs AND a 1/2 majority from browsers. While there have been some contentious votes along CA-browser lines, you can see from the ballot history that most ballots have passed and thus had support from both browsers and CAs: https://cabforum.org/ballots/

Oh let me guess how this goes: > Ballot 161 – Notification of incorrect issuance > In the event that a CA issues a certificate in violation of these requirements, the CA SHALL publicly disclose a report within one week of becoming aware of the violation. A link to the report SHALL simultaneously be sent to incidents@cabforum.org. > From the CAs, there were 0 YES votes, 14 NO votes and 5 Abstentions > From the Browser…

The ballot was a bit more nuanced than it seems. 1) Browsers already require reporting of mis-issuance directly to them. Mozilla requires a public bug list and 2) There was insufficient clarity in the ballot about "mis-issuance". Plus with crt.sh, this information is already available in one general location, which made the reporting requirement of everything seem a bit redundant.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#307
post #53

I was curious if this would affect my Symantec issued certs... according to my date math: Chrome 59 (Apr 13, 2017) +1023 days: 2020-01-31 Chrome 60 (May 25th, 2017) +837 days: 2019-09-09 Chrome 61 (Jul 20th, 2017) +651 days: 2019-05-02 Chrome 62 (Aug 31st, 2017) +465 days: 2018-12-09 Chrome 63 (Oct 12th, 2017) +279 days: 2018-07-18

[deleted]

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#308
post #284
post #209

"...pour encourager les autres"

In English please?

Byng's execution is referred to in Voltaire's novel Candide with the line "Dans ce pays-ci, il est bon de tuer de temps en temps un amiral pour encourager les autres" – "In this country, it is wise to kill an admiral from time to time to encourage the others."[1]

[1] https://en.wikipedia.org/wiki/Battle_of_Minorca_(1756)

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#309

Earlier quoted context omitted.

As someone who just renewed a Symantec EV cert (for a pretty penny), this would super piss me off. The steps Google has laid out seem proportionate to me. It clearly gets the message across without unduly burdening 3rd parties like me. And it has nudged me to look at other CAs. Unfortunately the first good option I've looked at--Digicert--has also been publicly rapped on the knuckles by Ryan Sleevi this month.

Pissing off Symantec customers is a necessary evil in this case. It's a sign that the strategy is working.

Some Symantec customers are in a position to file a complaint with Google well over the heads of the Chrome cert team. Some have many $millions of transactions dependent on Symantec certs, and aggressive legal staff.

Imagine if Chrome started reporting all Apple and Microsoft domains as insecure, with no warning. That's straying into very deep waters.

To be clear: I support Google's action against Symantec, and it is causing me to look at other CAs. But I need time to make an orderly change.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#310

Earlier quoted context omitted.

They'll all be caught by surprise and lose their shirts when Symantec releases their financials next quarter and the stock tanks. The market is full of ignorant people.

Just remember that the market can afford to be wrong longer than you can afford to bet against it.

Usually I agree, but SYMC is at an all time high and trading at 40x price per earnings. The price already implies a massive bet on increased profits, but there is no way that is going to happen.
Post reply on HN