Earlier quoted context omitted.
Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc. I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.
What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.
Chrome's Plan to Distrust Symantec Certificates
111–120 of 207 posts
Re: Chrome's Plan to Distrust Symantec Certificates
#112Earlier quoted context omitted.
What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.
Wouldn't you say it would be enough to pin those certs to TLDs?
Then absolutely not. Why should a US company not be allowed to use a Swiss-issued certificate for a .io domain name?
Re: Chrome's Plan to Distrust Symantec Certificates
#113Earlier quoted context omitted.
https://certsimple.com It’s incredibly fast, the guy who runs it is nice, great customer service. It just does what you need.
Thanks James! Mike from CertSimple here. HN folk can give me a shout anytime (mike@certsimple.com) or ask here - it's midnight in the UK but I'll be back up in the morn!
Re: Chrome's Plan to Distrust Symantec Certificates
#114Earlier quoted context omitted.
Thanks James! Mike from CertSimple here. HN folk can give me a shout anytime (mike@certsimple.com) or ask here - it's midnight in the UK but I'll be back up in the morn!
I believe that EV certificates cannot be wildcard certs, is this still true?
Re: Chrome's Plan to Distrust Symantec Certificates
#115What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
It looks like lots of big name sites don't use them. Why do some companies feel they need it, while letting internet giants such as Facebook, Google, Microsoft, etc. get away without it?
Re: Chrome's Plan to Distrust Symantec Certificates
#116I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…
No, they really shouldn't. Security is a ridiculously complex arena, and the amount of knowledge you need to make an intelligent setup on this is considerable. For tech-heads, fine, but the vast majority of people are not tech-heads.
If you switched over to this model, we'd end up in the bad old days of Windows XP, where untrained people would advise untrained people to 'just install this package and everything works!' and half the time they'd be installing malware. The right way to do this is 'sensible defaults, that the user can adjust'.
Re: Chrome's Plan to Distrust Symantec Certificates
#117If you are using the free SSL provided your Webhost "Let's Encrypt" certificate, you will be fine. That is not a Symantec cert.
When will google decide let's encrypt is not secure enough and start giving a warning around that.
Re: Chrome's Plan to Distrust Symantec Certificates
#118Earlier quoted context omitted.
What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.
Is it unreasonable to expect a foreign ecommerce site to use a CA that it's users can trust?
Oh, what's that? Symantec is an American company, headquartered in Mountain View, CA?
Re: Chrome's Plan to Distrust Symantec Certificates
#119Earlier quoted context omitted.
Thanks James! Mike from CertSimple here. HN folk can give me a shout anytime (mike@certsimple.com) or ask here - it's midnight in the UK but I'll be back up in the morn!
I believe that EV certificates cannot be wildcard certs, is this still true?
Re: Chrome's Plan to Distrust Symantec Certificates
#120Earlier quoted context omitted.
For all reasonable adversary examples shy of panopticon, downloading from multiple physical sites and global proxies and comparing the same roots across downloads should be sufficient, no?
Ohhhh gotcha, seems legit. I thought the certs in step 3 were individual site certs, not the roots. Thought he was going for some site-level pinning or something.