Distrust of Symantec TLS Certificates
31–40 of 124 posts
Re: Distrust of Symantec TLS Certificates
#32Earlier quoted context omitted.
I've wondered the same. Certificate trust was absolutely crucial to their business. The only thing I can think is that the leadership was oblivious to this. Maybe they didn't understand how certificates work.
Sell more certificates, make more money. Anything which gets in the way of making more money (like security) should be reduced or eliminated, with the right touch you can get bonuses / promotions for meeting fiscal goals and leave your successor to deal with the aftermath. They might understand how certificates work but that doesn’t mean they know how to set up an organization with the right incentives to do it corre…
https://www.theregister.co.uk/2016/05/27/blue_coat_ca_certs/
Re: Distrust of Symantec TLS Certificates
#33Re: Distrust of Symantec TLS Certificates
#34Chrome doing likewise: https://security.googleblog.com/2018/03/distrust-of-symantec...
1: https://support.apple.com/en-us/HT208860 2: https://knowledge.digicert.com/alerts/ALERT2562.html
EDIT: Its also worth mentioning that this isn't just limited Symantec certs but also will include GeoTrust, thawte, & VeriSign certs. Symantec's cert business has now been taken over by DigiCert so there is a means for valid reassurance.
EDIT2: Also it will effect RapidSSL. Totally forgot about them.
Re: Distrust of Symantec TLS Certificates
#35It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.
The problem is that they repeatedly mismanaged and violated the BRs. There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA. Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA…
Re: Distrust of Symantec TLS Certificates
#36It would be nice to have the date reflected in the title of this post (March 2018). It's relevant and a nice reminder because the full-distrust is coming soon, but there isn't anything new here AFAICT.
Re: Distrust of Symantec TLS Certificates
#37Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?
Re: Distrust of Symantec TLS Certificates
#38I was aware of the Symantec issue and checked my own certs and didn't see their name, but skimming the article I noticed RapidSSL and thought I'd double check and sure enough my certs are about to become bogus.
Re: Distrust of Symantec TLS Certificates
#39Wow, talk about an obscure warning that tells nothing to the domain owner.
Nobody who runs a website can pretend to be ignorant of this fiasco.
Re: Distrust of Symantec TLS Certificates
#40Earlier quoted context omitted.
The problem is that they repeatedly mismanaged and violated the BRs. There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA. Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA…
Pardon my ignorance, but what does "BR" stand for?