Live data from Hacker News

Symantec CA Response to Google Proposal and Community Feedback

symantec.com

21–30 of 129 posts

Re: Symantec CA Response to Google Proposal and Community Feedback

#21
post #18
post #9

Earlier quoted context omitted.

Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.

"Buying" as if Let's Encrypt isn't a thing. ;-)

well, for any organization that is doing serious ecommerce these days, you would want an EV SSL cert. Which is about $95/year from namecheap or a competitor. The GUI advantages for ordinary totally ignorant end users of seeing the happy green bar at the top are enough to justify the less than $10 per month ongoing cost.

Re: Symantec CA Response to Google Proposal and Community Feedback

#22

Earlier quoted context omitted.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

Mozilla seems in total agreement with Chrome on this, and it also takes unilateral CA authority action. This is not a negotiation where the orgs have the right side of the power dynamic.

It's always a negotiation. He who has the least to lose wins.

"Why isn't my browser working??" "So sorry about that, those darn nerds made a change on us."

I have seen this exact scenario play out. Mozilla and Google might be respected in the tech community; to most people they're an extremely tiny part of their life. "Your the IT man, just make it work"

Re: Symantec CA Response to Google Proposal and Community Feedback

#23
post #11

>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…

Yeah, they're using the argument: we're too big to fail.

there are a number of similarities between symantec and some wall street dinosaurs.

Re: Symantec CA Response to Google Proposal and Community Feedback

#24
post #18
post #9

Earlier quoted context omitted.

Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.

"Buying" as if Let's Encrypt isn't a thing. ;-)

In this context, I assume we're talking about EV certs. Though LE might be an emergency temp option for the big customers that forgot to plan around this.

Re: Symantec CA Response to Google Proposal and Community Feedback

#25
> These customers include many of the largest financial services, critical infrastructure, retail and healthcare organizations in the world, as well as many government agencies. This cohort is an important constituency that we believe has been under-represented to date in the public commentary that has been posted to the Google and Mozilla boards since large organizations rarely authorize employees to engage in such public discussions, particularly in an area related to security.

... well that's their problem, right?

You can't simultaneously say "These are some of the most important organizations in the world and you'll cause worldwide chaos" and "Won't someone listen to these poor companies, I am the Symantorax, I speak for the cohort, for the cohort has no tongues."

Re: Symantec CA Response to Google Proposal and Community Feedback

#26
Symantec is just going through the 5 stages of CA grief. First they were oblivious to it, then they were angry about it and called Google irresponsible. They're now at the proposal stage. Next will be depression and finally acceptance for their incompetence.

Re: Symantec CA Response to Google Proposal and Community Feedback

#27

>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…

There's an argument that it's good for end user security to force mobile apps to be updated, even if there weren't a specific reason to distrust Symantec's roots, because who knows when the next Heartbleed will come out.

Re: Symantec CA Response to Google Proposal and Community Feedback

#28
post #9

Earlier quoted context omitted.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.

Certificate pinning means it's a hell of a lot more than just "buying a new cert".

Re: Symantec CA Response to Google Proposal and Community Feedback

#29
post #6

Earlier quoted context omitted.

Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.

What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers. It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.

There's a massive logical leap between having an API and having certificates on public FTP servers.

An API is required for you to have proper infrastructure as code and leaving any bit to human input other than another validation step in the automated process is waiting for errors to happen (invalid or incorrectly spelled cert info, missing cert chains, wrong cert chains, etc.).

Symantec even calls out how much work these companies will have to do because so few of them have a proper certificate management system in place that's come back to bite them.

Re: Symantec CA Response to Google Proposal and Community Feedback

#30

>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…

>recoded, recompiled and redistributed.

I suppose that's true for mobile apps with embedded certs. Bet there's an app store / play store approval logjam for Symantec customers that miss this news, and all come crashing in after the expiry.

Post reply on HN