Distrust of Symantec TLS Certificates
11–20 of 124 posts
Re: Distrust of Symantec TLS Certificates
#12It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.
Source: https://sslmate.com/certspotter/failures
“Willfully” is the key word here. The business side of running a CA is fundamentally at odds with the security side. A few short-sighted decisions by business-minded managers with their eyes set on profits can completely eviscerate the security side of a company, and it’s possible that nobody remains at Symantec who has the combination of security knowledge + internal political power + will.
There’s also the Trustico fiasco. Trustico revoked 50,000 Symantec-issued certificates in a shockingly bad way. Because policies allowed for certificates with compromised public keys to be revoked, Trustico intentionally compromised the private keys in order to achieve the desired revocation.
https://groups.google.com/forum/#!topic/mozilla.dev.security...
> As one of Symantec's former largest partners - my personal opinion and personal experience is that Symantec is a company that thrives on recklessness and one that I wouldn't trust nor deal with.
You can see more bad behavior here—Symantec is seen as a reckless company, and Trustico (recklessly) cuts ties with Symantec for its business needs. Both actors are bad enough that their relationship reflects poorly on both of them.
I’m sure there are some people who could fix this problem in six months, but I bet they don’t work for Symantec or don’t have the power to do it.
Re: Distrust of Symantec TLS Certificates
#13It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.
Re: Distrust of Symantec TLS Certificates
#14Wow, talk about an obscure warning that tells nothing to the domain owner.
Re: Distrust of Symantec TLS Certificates
#15Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?
I've wondered the same. Certificate trust was absolutely crucial to their business. The only thing I can think is that the leadership was oblivious to this. Maybe they didn't understand how certificates work.
They might understand how certificates work but that doesn’t mean they know how to set up an organization with the right incentives to do it correctly.
Re: Distrust of Symantec TLS Certificates
#16Wow, talk about an obscure warning that tells nothing to the domain owner.
Re: Distrust of Symantec TLS Certificates
#17anyone know if Microsoft is following suit? I searched briefly and could not find any comments...
Apple are yet to state when they will perform the final, total distrust, but it is planned: https://support.apple.com/en-gb/HT208860
Re: Distrust of Symantec TLS Certificates
#18Re: Distrust of Symantec TLS Certificates
#19It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.
There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA.
Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA, and that got them through multiple errors that would have probably resulted in distrust for smaller CAs, and even the final distrust has had something like a years notice.
Re: Distrust of Symantec TLS Certificates
#20> In advance of removing all trust for Symantec-issued certificates in Firefox 63, a preference was added that allows users to distrust certificates issued by Symantec. To use this preference, go to about:config in the address bar and set the preference "security.pki.distrust_ca_policy" to 2.