Live data from Hacker News

Symantec CA Response to Google Proposal and Community Feedback

symantec.com

11–20 of 129 posts

Re: Symantec CA Response to Google Proposal and Community Feedback

#11

>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…

Yeah, they're using the argument: we're too big to fail.

Re: Symantec CA Response to Google Proposal and Community Feedback

#12
post #6

Earlier quoted context omitted.

Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.

What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers. It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.

Seriously. The fancy CA systems are wacky expensive.

Re: Symantec CA Response to Google Proposal and Community Feedback

#13
post #2

I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

There is a risk but they would already lose all Android users. If Apple and Mozilla then join in they pretty much would lose all iOS and macOS users.

For a bank maybe a user would temporarily accommodate but it would affect online stores and SaaS business a lot.

Re: Symantec CA Response to Google Proposal and Community Feedback

#14
post #6

Earlier quoted context omitted.

Given some of the internal CA systems I've dealt within the past, I'd almost prefer a public CA in some cases. Sometimes your internal CA is just the group with manual access to the certificate provisioning and signing systems with either no API or some awful re-implemented API.

What API do you need? The signing system should be airgapped or you end up with the same shit that is the public CA system such as roots sitting on public FTP servers. It's a bunch of command line scripts because if you are using it any different way you are probably doing it wrong.

Practically the answer is "they pass it around via email"...

Re: Symantec CA Response to Google Proposal and Community Feedback

#15
post #2

I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

Symantec's site won't get past "Loading Your Community Experience" with tracking blocked.

Re: Symantec CA Response to Google Proposal and Community Feedback

#16
post #2

I don't think Google was soliciting for a counter proposal from Symantec. Will be interesting to see their reply, and whether it's a literal reply or just a version push of chrome with their original plan.[1] [1] https://groups.google.com/a/chromium.org/forum/m/#!topic/bli... Edit: They did ask for community feedback, comments on risk, etc. But they do already have a timeline. See link above.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

Mozilla seems in total agreement with Chrome on this, and it also takes unilateral CA authority action. This is not a negotiation where the orgs have the right side of the power dynamic.

Re: Symantec CA Response to Google Proposal and Community Feedback

#17

>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…

Isn't that largely Google's stance with regard to Android? They blame the carriers and point to how slow they are, meanwhile tons of smart phones go without patching, which is no good for the general internet or users'

Re: Symantec CA Response to Google Proposal and Community Feedback

#18
post #9

Earlier quoted context omitted.

"This site does not support Chrome. Please use a browser that does not take unilateral CA authority action." might very well be the response of orgs married to Symantec. As a user, you need your bank (or other large org) more than you need your preference of browser.

Bold move though, when the fix is just buying a new cert. And the browser you're blocking has majority market share.

"Buying" as if Let's Encrypt isn't a thing. ;-)

Re: Symantec CA Response to Google Proposal and Community Feedback

#19

>require these applications to be recoded, recompiled and redistributed. Aka "updated". The entire post is basically "ok how about we be really good from now on and suffer no consequences, cause it'd be really shitty for us if we had to be penalised". They also posture a lot talking about how big their customers are, almost boasting about how inflexible and slow these big companies are, as if that's somehow Google's…

[deleted]

Re: Symantec CA Response to Google Proposal and Community Feedback

#20
> This cohort is an important constituency that we believe has been under-represented to date in the public commentary that has been posted to the Google and Mozilla boards since large organizations rarely authorize employees to engage in such public discussions, particularly in an area related to security.

Are these large organizations somehow incapable of putting out official statements regarding CAs? If they're being 'under-represented', it's their own fault for not speaking up.

Post reply on HN