Wow, talk about an obscure warning that tells nothing to the domain owner.
Distrust of Symantec TLS Certificates
21–30 of 124 posts
Re: Distrust of Symantec TLS Certificates
#22Chrome doing likewise: https://security.googleblog.com/2018/03/distrust-of-symantec...
Re: Distrust of Symantec TLS Certificates
#23PayPal's site is affected by this
Re: Distrust of Symantec TLS Certificates
#24Wow, talk about an obscure warning that tells nothing to the domain owner.
The message screenshotted in the article is a message to the website visitor, not to the domain owner. And not going out of their way to shame Symantec to every visitor to a site with a Symantec cert is probably a decent policy. Even without their cert business, Symantec is a big player that the browser vendors will have to work with in the future.
Re: Distrust of Symantec TLS Certificates
#25Wow, talk about an obscure warning that tells nothing to the domain owner.
Nobody who runs a website can pretend to be ignorant of this fiasco.
Re: Distrust of Symantec TLS Certificates
#26Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?
Re: Distrust of Symantec TLS Certificates
#27It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.
> Root cause: Symantec was willfully disregarding industry regulations by issuing trusted certificates without proper authorization. Source: https://sslmate.com/certspotter/failures “Willfully” is the key word here. The business side of running a CA is fundamentally at odds with the security side. A few short-sighted decisions by business-minded managers with their eyes set on profits can completely eviscerate the se…
Well, as we're seeing here, they can only be out of phase to a certain degree before both suffer.
Re: Distrust of Symantec TLS Certificates
#28Chrome doing likewise: https://security.googleblog.com/2018/03/distrust-of-symantec...
Chrome did this first, so any wide effect (in yall's organsiations) should already have been noticed by now, due to this.
The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.
Re: Distrust of Symantec TLS Certificates
#29PayPal's site is affected by this
That's surprising, because Chrome has distrusted Symantec certs for a few months and it's odd that Paypal would not have fixed it by now.
https://security.googleblog.com/2018/03/distrust-of-symantec...