>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
Symantec CA Response to Google Proposal and Community Feedback
11–20 of 129 posts
Re: Symantec CA Response to Google Proposal and Community Feedback
#12Earlier quoted context omitted.
Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.
What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers. It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.
Re: Symantec CA Response to Google Proposal and Community Feedback
#13I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
For a bank maybe a user would temporarily accommodate but it would affect online stores and SaaS business a lot.
Re: Symantec CA Response to Google Proposal and Community Feedback
#14Earlier quoted context omitted.
Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.
What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers. It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.
Re: Symantec CA Response to Google Proposal and Community Feedback
#15I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Re: Symantec CA Response to Google Proposal and Community Feedback
#16I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Re: Symantec CA Response to Google Proposal and Community Feedback
#17>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
Re: Symantec CA Response to Google Proposal and Community Feedback
#18Earlier quoted context omitted.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.
Re: Symantec CA Response to Google Proposal and Community Feedback
#19>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
Re: Symantec CA Response to Google Proposal and Community Feedback
#20Are these large organizations somehow incapable of putting out official statements regarding CAs? If they're being 'under-represented', it's their own fault for not speaking up.