Earlier quoted context omitted.
Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.
"Buying" as if Let's Encrypt isn't a thing. ;-)
Symantec CA Response to Google Proposal and Community Feedback
21–30 of 129 posts
Re: Symantec CA Response to Google Proposal and Community Feedback
#22Earlier quoted context omitted.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Mozilla seems in total agreement with Chrome on this, and it also takes unilateral CA authority action. This is not a negotiation where the orgs have the right side of the power dynamic.
"Why isn't my browser working??" "So sorry about that, those darn nerds made a change on us."
I have seen this exact scenario play out. Mozilla and Google might be respected in the tech community; to most people they're an extremely tiny part of their life. "Your the IT man, just make it work"
Re: Symantec CA Response to Google Proposal and Community Feedback
#23>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
Yeah, they're using the argument: we're too big to fail.
Re: Symantec CA Response to Google Proposal and Community Feedback
#24Earlier quoted context omitted.
Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.
"Buying" as if Let's Encrypt isn't a thing. ;-)
Re: Symantec CA Response to Google Proposal and Community Feedback
#25... well that's their problem, right?
You can't simultaneously say "These are some of the most important organizations in the world and you'll cause worldwide chaos" and "Won't someone listen to these poor companies, I am the Symantorax, I speak for the cohort, for the cohort has no tongues."
Re: Symantec CA Response to Google Proposal and Community Feedback
#26Re: Symantec CA Response to Google Proposal and Community Feedback
#27>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
Re: Symantec CA Response to Google Proposal and Community Feedback
#28Earlier quoted context omitted.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.
Re: Symantec CA Response to Google Proposal and Community Feedback
#29Earlier quoted context omitted.
Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.
What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers. It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.
An API is required for you to have proper infrastructure as code and leaving any bit to human input other than another validation step in the automated process is waiting for errors to happen (invalid or incorrectly spelled cert info, missing cert chains, wrong cert chains, etc.).
Symantec even calls out how much work these companies will have to do because so few of them have a proper certificate management system in place that's come back to bite them.
Re: Symantec CA Response to Google Proposal and Community Feedback
#30>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
I suppose that's true for mobile apps with embedded certs. Bet there's an app store / play store approval logjam for Symantec customers that miss this news, and all come crashing in after the expiry.