Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

321–329 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#321

It looks like the questions that Google/Mozilla asked Symantec and didn't like the answers to are posted here: https://knowledge.symantec.com/support/ssl-certificates-supp... (Archive link: http://archive.is/Cq9VO ) Really interesting reading!

Because the process happens in the public newsgroup mozilla.dev.security.policy anyone with a legitimate interest in the Web PKI can ask questions during incidents like this or indeed during Mozilla's new CA application process.

Some of the questions on that list are mine. I don't remember if representatives from Google or Mozilla explicitly told Symantec they needed to answer my questions, beyond a certain point it's implied that smart questions (and I hope mine are smart) should be answered regardless of who asks them.

Other than Google and Mozilla, major trust stores mostly prefer to conduct their activities in private, so we don't know what (if anything) Symantec were asked by Microsoft, Apple, etc.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#322
post #43
post #36

Earlier quoted context omitted.

Why does EV make a difference here? Can't you pin an intermediate or root cert from your CA of choice and avoid other CAs issuing end certs for your domain just as well?

I think the idea here is that they're not trying to prevent other CAs from issuing end certs, they're trying to only allow certs for their domain - from any CA on their short list - if the owner of the cert has been through Extended Validation.

Of course, this only works if the CA _actually_ makes sure they don't use the root you pinned for DV issuance. Just because it says "Ultra Great EV root" in the CN doesn't provide you that security, and it won't count as mis-issuance so long as the DV certificate doesn't have an EV policy OID baked into it.

If we'd asked in 2015, Symantec would probably have pointed us to CrossCert's CPS which said they only use certain Symantec roots. In fact Symantec had no mechanism in place enforcing that, CrossCert could and did issue from any Symantec root, whether it was on the list or not. So, if you chose a root thinking "I don't trust CrossCert, but they don't use this root so it's fine", oops, too bad.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#323
post #24

Earlier quoted context omitted.

> with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements Kinda undermines the idea of having a standards group if Google is going to strongarm the industry by doing their own thing anyways

"Baseline Requirements" sort of implies that what is specified is minimum, rather than exhaustive, rules, and that specific applications will have additional rules.

And they all do.

Mozilla's rules are public so you can go read them, and indeed you can help write them. But most famously they required all CAs to disclose loads of stuff, and they require CAs to do lots of stuff in public where everybody can see it, not behind closed doors where we don't know what they're up to.

Google's rules include lots of stuff about their Certificate Transparency idea, which has helped no end.

Microsoft's rules famously include them getting a veto where they can order any CA to revoke a certificate or else leave their trust programme. They mostly use this to zap malware / phishing sites.

Apple's rules forbid having lots of roots at once. Although apparently this didn't apply to Symantec, or various other people. Huh.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#324
post #17

Google's also been looking to limit the maximum validity lifetimes in general through the CA/B Forum[1] in a ballot that ended up not passing (with hints[2] that Chrome would end up enforcing something similar itself even if it wasn't part of the Baseline Requirements). This seems to be indicative of the general indication that Chrome wants to head in anyway[3]. [1] https://cabforum.org/pipermail/public/2017-January/…

Ballot 193 subseqently passed, limiting maximum (Web PKI) certificate lifetime to 825 days from March 2018.

That's definitely not enough to keep Ryan Sleevi happy, but it may be enough to buy CAs a bit more breathing space.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#325

Symantec thinks Google is being inflammatory. Symantec fired the people who made the test cert a couple of years ago. Here's Symantec's press release: Google’s statements about our issuance practices and the scope of our past mis-issuances are exaggerated and misleading. For example, Google’s claim that we have mis-issued 30,000 SSL/TLS certificates is not true. In the event Google is referring to, 127 certificates –…

The 30 000 certificates don't have any documentation. The BRs require that a CA keeps documentation showing how they validated the Subject, because without that any CA could issue anything and then say "Er, I forget why, but it was definitely OK" and who can prove they were wrong?

CrossCert wasn't able to produce any documentation for the certificates they got Symantec to issue. Maybe their dog ate it, or they kept it in the Recycle Bin on somebody's laptop and then mistakenly hit "Empty" one day. Most likely they simply never created the documentation at all, because Symantec had never asked them to produce it, so why bother?

But that means we have no reason, other than a general sense that CrossCert appear to have been incompetent rather than malevolent, to believe any of those certificates was actually validated. On that basis they're mis-issued, and so Symantec revoked them.

The 127 certificates discovered by investigators are clearly bogus, some aren't even for valid domain names, but the thousands of others weren't magically fine - we have no idea, and not having any idea is itself unacceptable.

It is true that Symantec shut down their entire RA partner programme (the relationship with CrossCert and half a dozen others) without explicitly being told to do that, and personally I felt that might be enough, but Google clearly don't see it the same way.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#326
post #161
post #8

Earlier quoted context omitted.

Prior to the Symantec aquisition, VeriSign used to pitch just this thing as a product. AFAIK the usage was limited to DoD and a few mundane things. The IC wasn't interested because it was easier for them to just steal certificates or work around TLS completely.

Interesting that it would be "so much easier" for the U.S. intelligence community to steal most certificates or work around TLS, when countries like Thailand, which have much fewer resources, prefer to get Microsoft to install their own root certificate for them in Windows. Perhaps this is what the IC meant as well, when it said there are other easier ways? Why bother with Verisign's solution, when they could have th…

Because using your own CA is not deniable. You aren't allowed to move forward with any solution that may lead to attribution.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#327
post #233

Earlier quoted context omitted.

Oh, I know. But name me a non-IT professional that knows the difference, or would care that their bank has "secure" and not "Bank of America LLC". I think there are groups of smart PKI/UI people discussing how better to design security warnings at various levels of EV/HTTPS/Partial HTTPS/HTTP.

A. EV certs are bought for a reason, the very "green bar". Customers will notice this and won't be happy about it. B. the 9 month expiration will also make customers unhappy Both measures will put operational pressure on Symantecs customers and eventually decrease Symantec's market share in the business.

[deleted]

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#328

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

As others have said, Digicert is good, as is IdenTrust (though neither are cheap). You might also look at HydrantID, which is rooted to QuoVadis, who've been around a good long time.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#329
post #263

Earlier quoted context omitted.

Those are not users. Those are people who have read up about SSL certificates and have bought in to the hype.

most business is B2B, I don't see how they're not users.

The business is not the user for SSL. It's the human logging into the website. Maybe Bank of America will care if the padlock in the URL bar is gone, but John Doe couldn't care less and probably has never noticed the green padlock and word secure in the URL bar ever.
Post reply on HN