Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

11–20 of 124 posts

Re: Distrust of Symantec TLS Certificates

#12

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

> Root cause: Symantec was willfully disregarding industry regulations by issuing trusted certificates without proper authorization.

Source: https://sslmate.com/certspotter/failures

“Willfully” is the key word here. The business side of running a CA is fundamentally at odds with the security side. A few short-sighted decisions by business-minded managers with their eyes set on profits can completely eviscerate the security side of a company, and it’s possible that nobody remains at Symantec who has the combination of security knowledge + internal political power + will.

There’s also the Trustico fiasco. Trustico revoked 50,000 Symantec-issued certificates in a shockingly bad way. Because policies allowed for certificates with compromised public keys to be revoked, Trustico intentionally compromised the private keys in order to achieve the desired revocation.

https://groups.google.com/forum/#!topic/mozilla.dev.security...

> As one of Symantec's former largest partners - my personal opinion and personal experience is that Symantec is a company that thrives on recklessness and one that I wouldn't trust nor deal with.

You can see more bad behavior here—Symantec is seen as a reckless company, and Trustico (recklessly) cuts ties with Symantec for its business needs. Both actors are bad enough that their relationship reflects poorly on both of them.

I’m sure there are some people who could fix this problem in six months, but I bet they don’t work for Symantec or don’t have the power to do it.

Re: Distrust of Symantec TLS Certificates

#13

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

Given how wide-spread the issues were, I'm not surprised that they couldn't turn it around within six months, even if they had the will from management to do so (which it isn't clear they did!).

Re: Distrust of Symantec TLS Certificates

#15
post #9
post #8

Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

I've wondered the same. Certificate trust was absolutely crucial to their business. The only thing I can think is that the leadership was oblivious to this. Maybe they didn't understand how certificates work.

Sell more certificates, make more money. Anything which gets in the way of making more money (like security) should be reduced or eliminated, with the right touch you can get bonuses / promotions for meeting fiscal goals and leave your successor to deal with the aftermath.

They might understand how certificates work but that doesn’t mean they know how to set up an organization with the right incentives to do it correctly.

Re: Distrust of Symantec TLS Certificates

#16

Wow, talk about an obscure warning that tells nothing to the domain owner.

While that is true, all service providers, VPS providers, cert resellers, hosting companies have known about this for over a year and should have replaced all of these certs by now as well as contacting cert holders.

Re: Distrust of Symantec TLS Certificates

#17
post #6

anyone know if Microsoft is following suit? I searched briefly and could not find any comments...

Microsoft rarely comment publicly prior to making changes to trust levels, but I've heard from several people that they will similarly distrust them.

Apple are yet to state when they will perform the final, total distrust, but it is planned: https://support.apple.com/en-gb/HT208860

Re: Distrust of Symantec TLS Certificates

#19

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

The problem is that they repeatedly mismanaged and violated the BRs.

There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA.

Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA, and that got them through multiple errors that would have probably resulted in distrust for smaller CAs, and even the final distrust has had something like a years notice.

Re: Distrust of Symantec TLS Certificates

#20
You can enable this now in Firefox 62 (latest stable)

> In advance of removing all trust for Symantec-issued certificates in Firefox 63, a preference was added that allows users to distrust certificates issued by Symantec. To use this preference, go to about:config in the address bar and set the preference "security.pki.distrust_ca_policy" to 2.

Post reply on HN