Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

61–70 of 124 posts

Re: Distrust of Symantec TLS Certificates

#61
post #59

Earlier quoted context omitted.

This is factually wrong. There wasn't plenty of warnings and google ignored their own roadmap. Google announced in October 2017 that they will block Symantec certificates in October 2018. Leaving a year to upgrade, fairly reasonable considering most certificates must be renewed early. However, Chrome blacklisted Symantec since April 2018, 6 months early. Taking a lot of people by surprise.

You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?

Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.

Re: Distrust of Symantec TLS Certificates

#62

FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...

Can you post the original roadmap that they didn’t follow? I can’t find a roadmap that doesn’t list April 2018 / Chrome 66 as the time when Symantec certificates issued prior to June 2016 will become distrusted.

https://security.googleblog.com/2017/09/chromes-plan-to-dist...

Re: Distrust of Symantec TLS Certificates

#63

FYI: Your site has been unreachable since April if you use Symantec certificates. Chrome announced the depreciation for October but they didn't stick to their own roadmap and blacklisted Symantec since April instead (Chrome 66 release). https://security.googleblog.com/2018/03/distrust-of-symantec...

Not sure why this is downvoted. It is correct.

Because it's wrong. The very post GP linked explicitly says that Symantec certs issued before June 1, 2016 would stop functioning in Chrome 66.

Re: Distrust of Symantec TLS Certificates

#64
post #59

Earlier quoted context omitted.

You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?

Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.

Are you sure? Paypal.com's Symantec-issued certificate still works in Chrome, at least on my PC: https://www.paypal.com/

Re: Distrust of Symantec TLS Certificates

#65
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

I was a technical lead for a project involving a) governments and b) lots of income from taxpayers, and I noticed this warning about Symantec certs a while ago from a Qualys scan I ran on the third-party payment website. I told my manager and our client about this several times before being laid off, and I would bet they never did anything about it. I'm wondering how this is affecting them.

Re: Distrust of Symantec TLS Certificates

#66
post #59

Earlier quoted context omitted.

You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?

Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.

Is it possible that you’re using a canary version of Chrome? Check chrome://version/, for me I see version 69 and I can go to https://www.paypal.com/ and see that the Symantec EV cert is still valid, which was issued in 2017. In particular, if you see version 70, I would expect you to get errors visiting PayPal, just like the roadmap says.

Personally I think it’s bad practice to have a cert last more than a year in the first place, due to a number of both operational concerns and security concerns, but that is neither here nor there.

Re: Distrust of Symantec TLS Certificates

#67
post #64

Earlier quoted context omitted.

Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.

Are you sure? Paypal.com's Symantec-issued certificate still works in Chrome, at least on my PC: https://www.paypal.com/

I couldn't be more sure. My company had hundreds of certificates issued from Symantec, who was our main supplier. Basically, all our websites broke the day Chrome was updated. It was hell.

If it were actually allowed, I would upload some of the certificates and write a blog post to show you.

Paypal has an EV, I don't have EV. Maybe these were not blacklisted. The rest was.

Re: Distrust of Symantec TLS Certificates

#68
post #63

Earlier quoted context omitted.

Not sure why this is downvoted. It is correct.

Because it's wrong. The very post GP linked explicitly says that Symantec certs issued before June 1, 2016 would stop functioning in Chrome 66.

Chrome also blacklisted certs issued after June 1, 2016.

Re: Distrust of Symantec TLS Certificates

#69
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this: Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate. Six months later Bob leaves to work at some other c…

Oh I know that it's widespread, it happened here; the guy who's job it was to care left and didn't pass on knowledge when he did. It is because there was a a role account assigned to comms about TLS certs that the notices were, well, noticed. I've worked in large orgs where comms are even worse.

But my point was that this is not some reckless sudden move by the browsers or DigiCert. In my observation, they have been earnestly and diligently working in good faith so people don't get bit by the transition.

Re: Distrust of Symantec TLS Certificates

#70
post #8

Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

Corporate leadership at the board room level is often resistant to the idea that oversight is their job, even though it is literally their only job. (Insert "You Had One Job" meme image). In many cases these people are paid (especially on a per hour basis) more than anybody else in the entire organisation, they ought to be working _very hard_ to deserve this money, and at most corporates they do little or nothing.

Did Symantec's shareholders get the board responsible for this... replaced? Did they at least get a big cut in their wages given that they're apparently no good at their jobs? Nope.

The Web PKI in my not at all humble opinion is doing a better job of handling this problem today than, for example, many actual bona fide regulators. When Symantec kept trying to offer up little bits and pieces (e.g. let's wind up this lucrative Korean partnership programme we've secretly been running for years that had no effective oversight...) they were told it wasn't enough.

In the end this distrust that you're seeing now was mandatory but it was not intended as a "death sentence" for the Symantec CA function pe se. Symantec were told to go find somebody whose leadership we could trust, and let the trustworthy outfit physically run the CA (with Symantec's brands) while Symantec got their shit together and tried again in a year or two. In the process of negotiating such a deal with DigiCert Symantec instead sold their entire CA business to them, which everybody seems to have (in some cases grudgingly) accepted is a good enough outcome.

DigiCert did a better than might be expected job of this from a technical point of view, and I hope that it works for them commercially as a result.

[Edited for clarity]

Post reply on HN