Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

51–60 of 124 posts

Re: Distrust of Symantec TLS Certificates

#51
post #22

Earlier quoted context omitted.

Chrome did this first, so any wide effect (in yall's organsiations) should already have been noticed by now, due to this.

As I understand it, Chrome and Firefox are both operating under the same policies with about the same timetables. Full distrust doesn't come until Firefox 63 / Chrome 70 - neither of which are stable releases yet. The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.

That's factually incorrect.

Google blacklisted ALL Symantec certificates since Chrome 66, in April. The roadmap announced the change for October but they did it 6 months earlier, ignoring their own roadmap.

As the OP says, organizations using Symantec have already been hit very hard, by surprise.

Re: Distrust of Symantec TLS Certificates

#52

Earlier quoted context omitted.

That's surprising, because Chrome has distrusted Symantec certs for a few months and it's odd that Paypal would not have fixed it by now.

Chrome and Firefox have only distrusted Symantec certs in their pre-release versions. The Chrome 70 and Firefox 63 releases in mid-October are when the hammer will fall. https://security.googleblog.com/2018/03/distrust-of-symantec...

[deleted]

Re: Distrust of Symantec TLS Certificates

#53

Earlier quoted context omitted.

That's surprising, because Chrome has distrusted Symantec certs for a few months and it's odd that Paypal would not have fixed it by now.

Chrome and Firefox have only distrusted Symantec certs in their pre-release versions. The Chrome 70 and Firefox 63 releases in mid-October are when the hammer will fall. https://security.googleblog.com/2018/03/distrust-of-symantec...

The hammer fell in April already. Google published a roadmap, the link you gave, but didn't respect it.

Re: Distrust of Symantec TLS Certificates

#54

Earlier quoted context omitted.

As I understand it, Chrome and Firefox are both operating under the same policies with about the same timetables. Full distrust doesn't come until Firefox 63 / Chrome 70 - neither of which are stable releases yet. The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.

That's factually incorrect. Google blacklisted ALL Symantec certificates since Chrome 66, in April. The roadmap announced the change for October but they did it 6 months earlier, ignoring their own roadmap. As the OP says, organizations using Symantec have already been hit very hard, by surprise.

Do you have a source for that? Google's KB articles still reference Chrome 70 [1], and I can't find another reference to this anywhere else.

Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set)

[1] https://support.google.com/chrome/a/answer/7662561?hl=en

Re: Distrust of Symantec TLS Certificates

#55
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

This is factually wrong. There wasn't plenty of warnings and google ignored their own roadmap.

Google announced in October 2017 that they will block Symantec certificates in October 2018. Leaving a year to upgrade, fairly reasonable considering most certificates must be renewed early.

However, Chrome blacklisted Symantec since April 2018, 6 months early. Taking a lot of people by surprise.

Re: Distrust of Symantec TLS Certificates

#56
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

This is a good point, and to add to this, some companies don’t take communication channels between the company and their certificate provider seriously. Sometimes the CA is left with the email address and phone number for someone who left the company over a year ago, and if you don’t have a good technical contact, you can spend a lot of time calling around until you find somebody who knows what’s going on with SSL.

That said, anyone who doesn’t have a big enough IT department to properly manage a certificate should be paying someone else to do it, it’s just that there are a lot of ways that contact information goes stale and documentation gets lost.

Re: Distrust of Symantec TLS Certificates

#57

FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...

Not sure why this is downvoted. It is correct.

Re: Distrust of Symantec TLS Certificates

#58
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this:

Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate.

Six months later Bob leaves to work at some other company. Bob's email is probably now blackholes, or maybe it's going into a never read "Bob's emails" folder of Bob's previous manager.

DigiCert, being conscientious, send email to bob@bigcorp.example warning that Verisign certs were a Symantec product (Symantec bought the brand and CA keys from VeriSign, or maybe from some other operator which in turn bought them from VeriSign, long ago)

But that email will either get delivered and silently go unread, or it'll bounce, but leaving no sign it needs to go to anybody else in particular instead of Bob.

Months later the cert stops working, as scheduled, and Steve, who is now responsible for this site, thinks DigiCert is somehow at fault. How were DigiCert supposed to guess that they needed to contact Steve?

Role accounts are the Right Thing™ so that the email goes to the person whose job is to care about the subject, not to some random individual who may not even work there any more. But they aren't enough, you also need mechanisms in place that ensure it's somebody's job to care, otherwise the role account emails just go in a folder and are never read.

So, sure, "incompetence" and not DigiCert's fault, nor Mozilla's but it's very widespread and you should be astonished if you work somewhere that does NOT have this problem in some form (maybe you have SSL certs locked down, but it turns out nobody is making sure you pay the electricity bills for outlying offices, or there's not actually anybody in charge of making sure payroll happens...)

Returning to SSL/TLS certificates though, any medium sized or larger organisation ought to be paying attention to the Certificate Transparency system. To do this properly you need to know all the eTLD+1s your organisation controls (this may be a non-starter in really sprawling organisations, but that's already a problem that needs fixing) but then you can know exactly what certificates exist for your names, who issued them, and why.

In most cases you don't _want_ Bob buying certificates on the company credit card anyway. Not just because it's cost inefficient (ignoring Let's Encrypt bigger organisations can get a commercial CA to cut them a deal for a fixed price or a steep discount per cert in exchange for doing one big Purchase Order rather than hundreds of credit card payments) but because it's organisationally a problem, it has security consequences, and it's another asset you're probably not tracking properly as a business.

Re: Distrust of Symantec TLS Certificates

#59
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

This is factually wrong. There wasn't plenty of warnings and google ignored their own roadmap. Google announced in October 2017 that they will block Symantec certificates in October 2018. Leaving a year to upgrade, fairly reasonable considering most certificates must be renewed early. However, Chrome blacklisted Symantec since April 2018, 6 months early. Taking a lot of people by surprise.

You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist...

That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?

Re: Distrust of Symantec TLS Certificates

#60

Earlier quoted context omitted.

That's factually incorrect. Google blacklisted ALL Symantec certificates since Chrome 66, in April. The roadmap announced the change for October but they did it 6 months earlier, ignoring their own roadmap. As the OP says, organizations using Symantec have already been hit very hard, by surprise.

Do you have a source for that? Google's KB articles still reference Chrome 70 [1], and I can't find another reference to this anywhere else. Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set) [1] https://support.google.com/chrome/a/answer/7662561?hl=en

I worked at a large company whose sole supplier was Symantec. Everything has been blacklisted since April.
Post reply on HN