Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

201–207 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#201
post #73

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

You will need an Extended Validation (EV) certificate to get your name in the bar. To get it to go green you "only" need a Domain Validation (DV) certificate. In simple terms: DV proves you own your DNS domain and EV proves that your real world entity owns the DNS domain. Lets Encrypt will only do DV and quite right too. EV costs a far bit more because it should require some proper checks - for example checking Compa…

> Go to chrome://flags and search for "Show certificate link". Don't know why it isn't the default.

Thanks for this tip! I like to check the certificate, so this will save me some clicks. I also don't know why it's not enabled by default.

Re: Chrome's Plan to Distrust Symantec Certificates

#202
post #187

Earlier quoted context omitted.

Does SSLKEYLOGFILE include the server certs or only the session? Apparently, "Chrome stores SSL certificate state per host in browser history" if you can figure out how to access that. https://serverfault.com/questions/279984 In any case: scan the hosts in your web history, and follow the cert chains to the various roots. Not sure if you're asking how or if you're asking whethor or not someone has already implemented…

> scan the hosts in your web history That's simple SQL query against the Firefox profile sqlite database. No problem. > and follow the cert chains to the various roots. Doesn't scale. If it can't be scripted, then it can't be done for tens of sites that I regularly visit, and hundreds more that I come across.

Makes sense. What operating systems do you need this for?

Re: Chrome's Plan to Distrust Symantec Certificates

#203

Earlier quoted context omitted.

Isn't 'removing existing trust' the same as 'distrust'? The word 'distrust' in no way implies that you have NEVER trusted them.

"Distrust" doesn't imply that you have never trusted them, but it does allow for you never having trusted them, and so communicates less.

Generally, yes if it's without context, but "Plan to Distrust" or "Going To Distrust" (and similar) certainly implies that there previously was some level of trust. I mean if you had no trust to begin with, why would you even say it that way (or say it at all)?

Re: Chrome's Plan to Distrust Symantec Certificates

#204

Earlier quoted context omitted.

"Distrust" doesn't imply that you have never trusted them, but it does allow for you never having trusted them, and so communicates less.

Generally, yes if it's without context, but "Plan to Distrust" or "Going To Distrust" (and similar) certainly implies that there previously was some level of trust. I mean if you had no trust to begin with, why would you even say it that way (or say it at all)?

As pointed out elsewhere, statements of future distrust admit the possibility that there wasn't yet opportunity to trust or distrust. For instance, if Symantec had never produced certificates and announced that they were going to, and Google announced "when they do, we won't trust them".

Re: Chrome's Plan to Distrust Symantec Certificates

#205

Earlier quoted context omitted.

The parent is not suggesting a deviation from the "it just works" model. They are suggesting a convenient way for expert or "paranoid" users to be able to make changes to whom they trust as they see fit - this does not affect average users at all, but may provide significant benefits to an important minority of users.

We can add or remove root certificates for OS, it's just deliberately not easy.

> it's just deliberately not easy

And thus crippled and useless against state attackers.

I fail to see the reason why my browser refuses to let me "pin" a CA only for certain sites for example.

Re: Chrome's Plan to Distrust Symantec Certificates

#206
post #90

Earlier quoted context omitted.

Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc. I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.

What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.

Did you not miss the part where I referred to my 'localized' version of Firefox or Chrome (i.e. US English)? For example: https://www.mozilla.org/en-US/firefox/organizations/all/

Again, I cannot read Mandarin or Turkish, and likely never ever will. It seems to me that it'd be much more likely that a site, even if run by Chinese or Turks, caters to American customers, should invest in a certificate trusted by a US CA, and similarly for every market they expect to do business in.

And likewise, I don't know why localized versions of browsers for the Chinese market would include trusted certs from Turkey or Brazil.

Seems like its a lot easier to force multinational companies, who already are going to have to invest in huge amounts of research and technology to deal with foreign taxes, currencies, bank accounts, etc., to add to their burden the responsibility for obtaining certs from their customers' local CAs, instead of having every single CA on Earth be trusted by all releases of browsers.

Re: Chrome's Plan to Distrust Symantec Certificates

#207
post #50
post #38

Earlier quoted context omitted.

No action will be taken to impact users until March 15, 2018 at the earliest and only if you got your certificate before June 1, 2016. At least when it comes to any existing certificate (they are ambiguous about when they will cut off new certificates exactly).

> they are ambiguous about when they will cut off new certificates exactly They are? It seems pretty clear to me. Symantec's old infrastructure will be distrusted in Chrome beta in September 2018. At that point, no certificates issued by Symantec's old root certs (including those issued after June 1, 2016) will be trusted.

They mentioned to not get any certificates from the old infrastructure after the new infrastructure is available as they will be untrusted earlier (to ensure that Symantec starts using the new infrastructure exclusively once it is available).

However they didn't say when they would do that.

Post reply on HN