Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

1–10 of 124 posts

Re: Distrust of Symantec TLS Certificates

#3
When such an error (see article) is presented, it’s a teachable moment not only for the user surfing the site, but also for the owner of the site who is going to field questions about the error message from users.

It would be great if Mozilla would include some wording that instills alarm in site owners about how the site’s information, not just the user’s, is at risk.

For example, most non-malicious site owners probably would not want maliciously altered content served from or made to appear as though it came from their site. Yet most of them are, I suspect, unaware that this is a danger when their site does not use TLS.

It would be great to see Mozilla take this chance to highlight this danger so that the people most in a position to make changes would become aware of this additional good reason to do so.

Re: Distrust of Symantec TLS Certificates

#7
post #3

When such an error (see article) is presented, it’s a teachable moment not only for the user surfing the site, but also for the owner of the site who is going to field questions about the error message from users. It would be great if Mozilla would include some wording that instills alarm in site owners about how the site’s information, not just the user’s, is at risk. For example, most non-malicious site owners prob…

> It would be great if Mozilla would include some wording that instills alarm in site owners about how the site’s information, not just the user’s, is at risk.

I'd expect the reseller to inform the buyer about the distrust of these certificates. The SSL reseller we use informed us before April this year.

Re: Distrust of Symantec TLS Certificates

#8
Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't!

I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

Re: Distrust of Symantec TLS Certificates

#9
post #8

Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

I've wondered the same. Certificate trust was absolutely crucial to their business. The only thing I can think is that the leadership was oblivious to this. Maybe they didn't understand how certificates work.

Re: Distrust of Symantec TLS Certificates

#10

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

Sold and DigiCert has been reissuing new certs. Unfortunately they can’t change them for you. Poor operators won’t know until the rug is finally pulled from under them. DigiCert and browser vendors have done a decent job of telegraphing the changes..
Post reply on HN