Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

81–90 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#81
post #63
post #60

Is there a list somewhere of the actual Root CA certificates that will be removed as part of this? Is it just any Root CA certificate that has "Symantec, Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" in it's name?

I think this is what you're looking for: https://chromium.googlesource.com/chromium/src/+/master/net/...

That's it, thanks!

Re: Chrome's Plan to Distrust Symantec Certificates

#82
post #76
post #72

Earlier quoted context omitted.

It's useful for no-name companies, an EV certificate highlights a company that went through unnecessary pain just to get a little green checkbox - I know I personally trust smaller online retailers more when they have one since they've had to prove their identity to a CA. Nobody notices the lack of EV on amazon.com, because, well, it's Amazon.

> Nobody notices the lack of EV on amazon.com, because, well, it's Amazon. Which means that nobody notices the lack of EV on amazoone.com, because, well, it'as Amazon.

amazoone.com actually redirects to www.amazon.com, as do amazoon.com, aamazon.com, and amezon.com. It seems like finding a domain name that is "close" to amazon.com that is not already registered by Amazon is not that easy.

Re: Chrome's Plan to Distrust Symantec Certificates

#83

Earlier quoted context omitted.

Considering that literally anyone who gets even local access to any server at all, or can spoof one - even servers that have never used LetsEncrypt before - can generate new valid LetsEncrypt certificates, and nothing generated has a password on it, I don't know if I would consider them trustworthy. If you want to passively monitor encrypted traffic on a massive scale and not get caught (other than via their log - an…

I think it's a valid criticism, not LE but industry as a whole. Intel should add usable HSM in every cheap laptop, not even talking about servers instead of their ME backdoors. Technology is there, it's cheap and it's needed.

Nearly all laptops, desktops, and servers sold in the last decade have a Trusted Platform Module (TPM) which is in fact a HSM. You need drivers and utilities to use it but it's there.

TPMs generally aren't fast enough to do RSA signatures a on busy webserver though, but they're wonderful for protecting VPN certificates (tools for managing this are built into windows Group Policy, I imagine it's very painful on Linux)

Re: Chrome's Plan to Distrust Symantec Certificates

#84

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using?

Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)

Re: Chrome's Plan to Distrust Symantec Certificates

#85

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?

I definitely do for my bank. And the country code that is shown next to it.

Re: Chrome's Plan to Distrust Symantec Certificates

#86

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc.

I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.

Re: Chrome's Plan to Distrust Symantec Certificates

#87
post #22
post #3

"including Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" RIP RapidSSL wildcard

Wow, I never realised VeriSign was a Symantec brand. I'm not sure what it says that Google doesn't trust the company that operates the registry for .com

Verisign's SLL authentication business was spun off and sold to Symantec a while ago, but Verisign continues to operate the .com registry as a separate company.

Re: Chrome's Plan to Distrust Symantec Certificates

#88
post #84

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)

EV is an option for companies that worry about branding - specifically ones that are well-known to do business offline. This extra layer of trust, relayed to the user from the web browser, reinforces the fact that they are on the correct website.

For example, I can go grab something like "bannk.com" (notice two 'n's) and get a DV cert for it - because I hypothetically own that name. Now, I can copy the real "bank.com" onto the site and perform a phishing attack. They both appear to be encrypted but the EV'd one has the organization noted, the fake one will not be able to have that legitimacy.

I am not saying the system isn't without its faults (people might not even notice), but it's an extra measure a company can do to keep itself distinguished from phshing websites or copycat services.

Re: Chrome's Plan to Distrust Symantec Certificates

#89
post #84

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

> LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)

> without any shown benefit

on the contrary, I know that the presence of an EV line has helped my mother avoid a pretty decent phishing attempt. Any company holding confidential details or data should have one, its just a shame they are so expensive (which due to their verification is unlikely to come down too far).

Re: Chrome's Plan to Distrust Symantec Certificates

#90

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc. I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.

What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language?

That just makes the normal user who wants to buy stuff learn to ignore SSL errors.

Post reply on HN