>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
This comment irritates me. 1) The point of the first part of their post is not "we're too big", it's "a move like this would disrupt the lives of an awful lot of people." Even more so, consider what would happen if Google were to update Chrome to not accept these certs. For internal applications, the IT departments of all these companies—which likely total a few hundreds of thousands of users in total—would simply ma…
Symantec CA Response to Google Proposal and Community Feedback
91–100 of 129 posts
Re: Symantec CA Response to Google Proposal and Community Feedback
#92Earlier quoted context omitted.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Mozilla seems in total agreement with Chrome on this, and it also takes unilateral CA authority action. This is not a negotiation where the orgs have the right side of the power dynamic.
Re: Symantec CA Response to Google Proposal and Community Feedback
#93Earlier quoted context omitted.
Iirc you can have certs signed by multiple roots though, right? In which case these sites can just get their cert signed by the pinned symantec root and a real still-valid root. Nobody's stopping symantec from signing new certs, they just won't work in Chrome (and likely other browsers) Or maybe I've misunderstood the situation.
Unfortunately, you can't keep multiple chains in a single X.509 certificate. While you can have a given key signed by multiple CAs, AIUI, this just lets you switch easily, not tell a client about both, and just work if they trust either CA.
I've always been of the opinion that the rogue/careless CA problem can be solved by mandating N root sigs and recommending M>N. In a system with multiple independent LetsEncrypt like entities this is doable. If a CA needs to be revoked you can do it in a much easier way here, since it's still ok to transitively allow sites with N-1 certs and one now-disallowed cert signed by that CA. Doesn't fix all the problems but it certainly removes the inertia behind kicking out bad CAs.
Looks like we'd need a x509 extension to do this then. :/
Re: Symantec CA Response to Google Proposal and Community Feedback
#94>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
This is happening because Symantec was grossly negligent. They're going to be held to account for that.
All those giant companies should be firing up their lawyers and starting emergency procedures to change to a different provider. Anyone still using Symantec at this point is absolutely playing with fire.
Re: Symantec CA Response to Google Proposal and Community Feedback
#95Earlier quoted context omitted.
> There's millions of internet-connected set top boxes, tvs, and dvd/bluray players deployed around the world that run with a limited set of supported CAs. What exactly is the issue? If an embedded device trusts Symantec CA, then connections from the device to its central servers will continue working without interruption. In this example, the device trusts the Symantec CA, and the server presents a certificate signe…
You have api.mysite.com which serves both an embedded device as well as your site. To allow the site to be viewed in Chrome, you need a new cert for your API, and so you now have to either update your site to point to a different endpoint, or update your devices to accept the new cert. Sure it might be easier to do the former for some companies, but either way there's certainly a cost.
Re: Symantec CA Response to Google Proposal and Community Feedback
#96Earlier quoted context omitted.
This comment irritates me. 1) The point of the first part of their post is not "we're too big", it's "a move like this would disrupt the lives of an awful lot of people." Even more so, consider what would happen if Google were to update Chrome to not accept these certs. For internal applications, the IT departments of all these companies—which likely total a few hundreds of thousands of users in total—would simply ma…
Part of the premise of Google's plan is that Symantec's customers will experience disruption. If you poll Symantec's customers, the overwhelming majority of them will day "no, don't punish our CA". We didn't need Symantec to tell us that. On the other hand, Symantec's CA was caught mis-issuing certificates. That affects everyone, not just Symantec's own customers.
Re: Symantec CA Response to Google Proposal and Community Feedback
#97Earlier quoted context omitted.
No, there's a huge difference. The difference here is that the Manufacturers and the Carriers are gatekeepers to the customer's phones. The manufacturer made customizations to Android for their phone. Android isn't a cleanly-separated stack where the manufacturer modifies only a certain part of the stack for their phone but Google could go and update another part without risk of breaking anything (is any software pro…
Google holds all the cards. They have to sign off, or the phones will lose access to the Play Store and Google services like Maps. Google only needs to play the cards it already holds.
Re: Symantec CA Response to Google Proposal and Community Feedback
#98Earlier quoted context omitted.
"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.
Symantec's site won't get past "Loading Your Community Experience" with tracking blocked.
Works for me without Javascript.
Re: Symantec CA Response to Google Proposal and Community Feedback
#99> This cohort is an important constituency that we believe has been under-represented to date in the public commentary that has been posted to the Google and Mozilla boards since large organizations rarely authorize employees to engage in such public discussions, particularly in an area related to security. Are these large organizations somehow incapable of putting out official statements regarding CAs? If they're be…
To me it was really bold of them to take the tone and stance that they did with regard to these large organizations. They're making the case as to why Google needed to do what it did ... all of these large organizations that will be severely impacted by having to replace all of these certificates are relying on a CA that has shown itself to not be worthy of the trust that CAs are relied upon to provide. I'm at a loss…
Re: Symantec CA Response to Google Proposal and Community Feedback
#100>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…
For some reason, technical professionals associated with large organizations seem to actively enjoy pretending that basic upkeep is beyond the means of their organization (or has a poor value proposition). I suspect that it comes from a perverse enjoyment of being "pragmatic" in the face of "idealism" but really they're just saying "My org refuses to pay the costs associated with correctly operating the technologies…
The current Symantec SHA1 intermediate CA cert is valid between Feb 2010 and Feb 2020, so it seems like there was probably a cert change ~7 years ago too. The horror!