Live data from Hacker News

DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

investor.symantec.com

31–40 of 59 posts

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#31

Earlier quoted context omitted.

You seem to be conflating expectations and reality. They did kill the business, but Symantec was able to salvage part of it.

They should have been utterly destroyed; not parted out to the highest bidder. I want every Symantec shareholder to feel the pain of a zero share price for what they enabled.

The point I'm trying to make is that they're not dead if they own 30% of digicert as a result of this instead of being left with nothing.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#32
post #7

How is Symantec's cert business not a toxic asset given their historical practices?

Well this business unit might be a toxic asset now.

But I'm sure it'll go right back to printing money once it's no longer directly associated with a vendor of TLS interception middle boxes popular among despots. And the browser relations fiasco will blow over eventually.

Might cost them a bunch of rebates and refunds to keep clients, but I see why this could be a viable customer acquisition move for DigiCert.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#33

Earlier quoted context omitted.

They should have been utterly destroyed; not parted out to the highest bidder. I want every Symantec shareholder to feel the pain of a zero share price for what they enabled.

The point I'm trying to make is that they're not dead if they own 30% of digicert as a result of this instead of being left with nothing.

What exactly does Google accomplish by somehow trying to prevent Symantec from having a beneficial interest in its customer base? The alternative to this deal is that Symantec continues limping forward with a broken CA customer base that browsers have to accommodate for years to come. The economics of this deal are what enabled it to happen at all.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#35
post #4

Earlier quoted context omitted.

It's Symantec's past operation of the CA that's untrusted by Google, and in fact one of the proposals was that Symantec make a new CA and cross-sign it with their old one, which would maintain compatibility for previous customers that pinned the Symantec root as well as customers using up-to-date browsers. So if the setup here is that DigiCert signs their own CA with Symantec's, then everyone's happy: DigiCert gets t…

I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.

The checkboxes you're implicating here are the ceremonial kind. (I do security in the financial infrastructure space, for whatever that's worth).

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#36

I'm a reseller for Digicert - they just sent an announcement email about this, here's the most interesting bit: "Earlier this year, the browsers proposed a plan to limit trust in Symantec certificates after discovering issues with how they were validating and issuing digital certificates. Importantly, we feel confident that this agreement will satisfy the needs of the browser community. DigiCert is communicating this…

You may want to come up with an escape plan then. If digicert can buy Symantec so that Symantec can escape censure what message does that send? At this point Symantec should be considered so radioactive that nobody would go near it for fear of contamination. Symantec betrayed all of us and digicert, in buying it and rewarding the behaviour is doing the same.

I think your outrage is properly directed, and I agree with you that this is way too nice an ending for Symantec.

However, I don't think that anyone is actually going to make Symantec as contaminated as you or I want. If the people at DigiCert who were competent yesterday are operating Symantec's infrastructure today, that infrastructure is now trustworthy. And in buying and salvaging it, DigiCert did the community a service: instead of leaving us in this ambiguous position where a too-big-to-fail CA was calling up Google executives to potentially overrule engineering decisions, that CA is now no longer a threat.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#37
post #35

Earlier quoted context omitted.

I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.

The checkboxes you're implicating here are the ceremonial kind. (I do security in the financial infrastructure space, for whatever that's worth).

I suppose we'll agree to disagree (RegSCI in this case). Happy to grab a beer if you want to lecture me on how I'm wrong, I try to be open minded.

Whether it's ceremony or not, I have to check the box or face harsh regulatory penalties.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#38
post #4

Earlier quoted context omitted.

It's Symantec's past operation of the CA that's untrusted by Google, and in fact one of the proposals was that Symantec make a new CA and cross-sign it with their old one, which would maintain compatibility for previous customers that pinned the Symantec root as well as customers using up-to-date browsers. So if the setup here is that DigiCert signs their own CA with Symantec's, then everyone's happy: DigiCert gets t…

I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.

I suspect your auditors have no real reason to object to Let's Encrypt (do they understand that Let's Encrypt is equally capable of issuing a false certificate under your name? does your security rely on the browser PKI? how did every single company in the browser PKI get okayed by your auditors?).

You have a perfectly valid reason, which is that your auditors want you to buy an expensive certificate to make them happy, but you're still paying more than market ($0ish) for SSL, which means you're a good customer for DigiCert to have acquired.

BTW, if you want to save some money, try sending your auditors the WebTrust audits that Let's Encrypt has passed just as well as Symantec (if not more well, see mozilla.dev.security.policy): https://letsencrypt.org/repository/

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#39
post #38

Earlier quoted context omitted.

I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.

I suspect your auditors have no real reason to object to Let's Encrypt (do they understand that Let's Encrypt is equally capable of issuing a false certificate under your name? does your security rely on the browser PKI? how did every single company in the browser PKI get okayed by your auditors?). You have a perfectly valid reason, which is that your auditors want you to buy an expensive certificate to make them hap…

As you can probably imagine, money isn't an issue. Our budget for our PKI team is larger than a small startup's entire annual payroll cost.
Post reply on HN