Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

111–120 of 124 posts

Re: Distrust of Symantec TLS Certificates

#111
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

[deleted]

Re: Distrust of Symantec TLS Certificates

#112

There's two problems this exposes. One, it takes a very long time to dis-trust a root cert. This means some people's connections could be exposed for a very long time. Two, the method for update shown here is to upgrade your browser. Not everyone can upgrade their browser. Corporations often lock down browser updates, and take a very long time to upgrade. Sure, it's fine for you to say "that's the corporation's fault…

It sounds like you could be describing a desire for trust stores in operating systems that users and system administrators can manage. Is that the case?

Moving on past that, I think you've hit the nail on the head. CAs are about having a root for tree of trust. CAA and DANE are about ensuring that. I'm very curious how you imagine an improved, innovative solution to assuring trust!

I've seen proposals like Namecoin, which are innovative but fail the test of being improved.

Re: Distrust of Symantec TLS Certificates

#113
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

I understand the rationale behind all of this, but I would get pissed off if Google sent me an email that basically says "do what we tell you to do or we will take your website offline"

Re: Distrust of Symantec TLS Certificates

#114
https://www.ssllabs.com/ssltest/analyze.html?d=www.paypal.co...

I was getting frustrated because I could not visit Paypal (and Ebay) with Firefox nightly, because thy still use the old Symantec TLS certificates. I wonder whether there is _any_ major party that should be more concerned with their certificates than Paypal.

Re: Distrust of Symantec TLS Certificates

#115
post #106

My favorite story is when Mark Shuttleworth sold Thawte to VeriSign and used the money to start Canonical. This shows one of the problems of the current debt-based economy.

> Mark Shuttleworth

> Canonical

> debt-based economy

What do any of those things have anything to do with Symantec certificates being distrusted?

Re: Distrust of Symantec TLS Certificates

#116
post #115
post #106

My favorite story is when Mark Shuttleworth sold Thawte to VeriSign and used the money to start Canonical. This shows one of the problems of the current debt-based economy.

> Mark Shuttleworth > Canonical > debt-based economy What do any of those things have anything to do with Symantec certificates being distrusted?

Nothing, just mentioning the history. It is worth mentioning since VeriSign was one of the first CAs.

Re: Distrust of Symantec TLS Certificates

#117

Earlier quoted context omitted.

As I understand it, Chrome and Firefox are both operating under the same policies with about the same timetables. Full distrust doesn't come until Firefox 63 / Chrome 70 - neither of which are stable releases yet. The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.

That's factually incorrect. Google blacklisted ALL Symantec certificates since Chrome 66, in April. The roadmap announced the change for October but they did it 6 months earlier, ignoring their own roadmap. As the OP says, organizations using Symantec have already been hit very hard, by surprise.

This isn't true. Chrome itself proves this when loading a site affected by wave 2 of the distrust:

"The SSL certificate used to load resources from https://(domain) will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information."

Everything was being done in 2 waves. First wave was Chrome 66, second wave is Chrome 70. See Google's link above for the specifics.

Source: Chrome's own warnings and that I work for a business that deals heavily in SSL sales.

Re: Distrust of Symantec TLS Certificates

#118
post #82

It's been obvious to me for quite a while that EV etc only really tells you "this person paid $$$ to get a cert" rather than anything about the site being trustworthy or being who it says it is. I wouldn't bat an eye if 10 years from now major browsers distrusted everything but letsencrypt. Once the letsencrypt project comes out with a comparable solution for code signing, there is really no more reason for paid cert…

Have you ever actually bought an EV certificate? I work for a company that sells them and therefore I have to deal with the process and there are a lot of checks. "They don't check shit" is complete nonsense.

Re: Distrust of Symantec TLS Certificates

#119

I've got a question about this, as I've been hurled into the admin of our certs, and honestly I probably shouldn't be the one to do it, lol. But, we run root certs from DigiCert with the rest of the chain provided by RapidSSL. However, I have not received any depreciation warnings via email or any notification in the console output on these sites. Is there a utility available to "check" our sites, in the same way ven…

Chrome's dev console shows a warning for affected certs.

Re: Distrust of Symantec TLS Certificates

#120
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

I understand the rationale behind all of this, but I would get pissed off if Google sent me an email that basically says "do what we tell you to do or we will take your website offline"

That would be bad. It's not what's happening.

What's happening is "update your security on the thing that you have already got security on, or else at least two of the most popular browsers will mark it as insecure; also, you will lose points in our search engine".

Post reply on HN