Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

41–50 of 124 posts

Re: Distrust of Symantec TLS Certificates

#41
FYI: Your site has been unreachable since April if you use Symantec certificates.

Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...

Re: Distrust of Symantec TLS Certificates

#42

Wow, talk about an obscure warning that tells nothing to the domain owner.

While that is true, all service providers, VPS providers, cert resellers, hosting companies have known about this for over a year and should have replaced all of these certs by now as well as contacting cert holders.

They're still exceptionally user-hostile warnings. You can get this running a pre-release browser (and I doubt that they'll be changed for the stable releases of either FF or Chrome) trying to visit Paypal. It's utterly bananas to present this to an end-user doing a very common, security-dependent interaction.

Re: Distrust of Symantec TLS Certificates

#43
post #19

Earlier quoted context omitted.

The problem is that they repeatedly mismanaged and violated the BRs. There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA. Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA…

Pardon my ignorance, but what does "BR" stand for?

[deleted]

Re: Distrust of Symantec TLS Certificates

#44

Earlier quoted context omitted.

Pardon my ignorance, but what does "BR" stand for?

Pretty sure it refers to "Baseline Requirements" as specified by the CA Browser Forum. https://en.m.wikipedia.org/wiki/CA/Browser_Forum

You beat me to it! :)

https://cabforum.org/baseline-requirements-documents/

Re: Distrust of Symantec TLS Certificates

#45
post #37
post #8

Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

My impression: For years it was common practice that when CAs messed something up it would cause some complains, but no real consequences. The large CAs thought they were "too big to fail". They thought it would just go on like that. They (and many others in the industry) didn't believe that Google was serious when they threatened with browser removal. When they realized Google was serious it was too late to change t…

It also probably helped that the CA business wasn't Symantec's bread-and-butter.

Re: Distrust of Symantec TLS Certificates

#46

FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...

Yeah I have seen ecommerce sites that were using Symantec. Nobody cares about Firefox I guess but once Chrome starts enforcement shit will hit the fan.

Re: Distrust of Symantec TLS Certificates

#47
There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners.

I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning.

My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this year, and that we would need to claim our free replacements issued from the new trust root that is replacing Symantec's. And it's not been just one notice, we've been getting them regularly. And in addition to the automatic form emails, the sales rep assigned our account personally reached out to us to make sure we were getting this taken care of. We are not a large company, either; we have less than 100 employees. DigiCert is taking this transition seriously.

So IMO, if someone gets blindsided by their website breaking because of the Symantec root distrust, then they have only laziness and/or incompetence to blame, whether it's their own, or that of their website operator. Those who's job it is to make sure that doesn't happen have been warning about it for nearly a year now.

Re: Distrust of Symantec TLS Certificates

#48
post #32

Earlier quoted context omitted.

Sell more certificates, make more money. Anything which gets in the way of making more money (like security) should be reduced or eliminated, with the right touch you can get bonuses / promotions for meeting fiscal goals and leave your successor to deal with the aftermath. They might understand how certificates work but that doesn’t mean they know how to set up an organization with the right incentives to do it corre…

Interestingly, I looked up the symantec CEO. He was previously the ceo of Blue Coat. Blue Coat is a maker of man in the middle proxy appliances for businesses to spy on their employees. They controversially got root certificate authority. Which could of course be used to mitm SSL sites (which they promised and crossed their heart they would never do). https://www.theregister.co.uk/2016/05/27/blue_coat_ca_certs/

Didn't someone at the Tor Project analyse these Blue Coat MiTM boxes and find a cross-signed intermediate signing certificate preloaded, with the option to load your own signing cert so one could MiTM with ease? This was more than a few years back...

Re: Distrust of Symantec TLS Certificates

#49
post #25
post #21

Earlier quoted context omitted.

Nobody who runs a website can pretend to be ignorant of this fiasco.

I mean with the huge number of set-and-forget Wordpress installations I could absolutely believe people are ignorant of this. I mean why would anyone outside of professional webdevs even care? It's not like this news escaped the tech bubble.

Those forgotten Wordpress installs may not even have https support.

Re: Distrust of Symantec TLS Certificates

#50

FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...

Yeah I have seen ecommerce sites that were using Symantec. Nobody cares about Firefox I guess but once Chrome starts enforcement shit will hit the fan.

Point being. Chrome already started enforcement in April.
Post reply on HN