Live data from Hacker News

Symantec CA Response to Google Proposal and Community Feedback

symantec.com

1–10 of 129 posts

Re: Symantec CA Response to Google Proposal and Community Feedback

#2
I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1]

[1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli...

Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

Re: Symantec CA Response to Google Proposal and Community Feedback

#4
>require these applications to be recoded, recompiled and redistributed.

Aka "updated".

The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised".

They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's or general Internet users' problem.

Re: Symantec CA Response to Google Proposal and Community Feedback

#5
There is a significant amount of "we will" language in here, rather than "we have started" or "have already begun". The choice of language speaks volumes that they only appear to be willing to take necessary audit action if Google agrees to it, rather than something that needs to be done regardless.

Re: Symantec CA Response to Google Proposal and Community Feedback

#6

I love how none of the example "dependencies" they give should be using public CA in the first place.

Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.

Re: Symantec CA Response to Google Proposal and Community Feedback

#7
post #2

I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec.

As a user, you need your bank (or other large org) more than you need your preference of browser.

Re: Symantec CA Response to Google Proposal and Community Feedback

#8
post #6

I love how none of the example "dependencies" they give should be using public CA in the first place.

Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.

What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers.

It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.

Re: Symantec CA Response to Google Proposal and Community Feedback

#9
post #2

I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.

Re: Symantec CA Response to Google Proposal and Community Feedback

#10
post #2

I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

You're better off moving your accounts to a local credit union that does security correctly.
Post reply on HN