Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

11–20 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#14
Interesting RCA from Symantec on the originating incident: https://bug1334377.bmoattachments.org/attachment.cgi?id=8831... (PDF)

Also, they provided several Q&A-style responses as well:

https://bug1334377.bmoattachments.org/attachment.cgi?id=8831...

https://bug1334377.bmoattachments.org/attachment.cgi?id=8836...

https://bug1334377.bmoattachments.org/attachment.cgi?id=8838...

Re: Chrome's Plan to Distrust Symantec Certificates

#15
post #4

Earlier quoted context omitted.

When will google decide let's encrypt is not secure enough and start giving a warning around that.

Considering Google is a major sponsor of the project, I'd say likely never. Not to mention that Google has been pushing hard for https on all sites, which is exactly LE's goal.

Not only that, but they're doing things like Certificate Transparency - publishing every certificate they sign into public logs and they're funded and supported by some of the biggest names in online security and privacy.

They're probably the most trustworthy CA on the planet.

Re: Chrome's Plan to Distrust Symantec Certificates

#17

I realize that the title here is what Google put on their blog, but it seems to me that "detrust" would be more accurate than "distrust".

“distrust” is an established English words that means exactly what Google intends. “detrust” is, while not hard to figure out, an unnecessary neologism.

Re: Chrome's Plan to Distrust Symantec Certificates

#18
post #4

If you are using the free SSL provided your Webhost "Let's Encrypt" certificate, you will be fine. That is not a Symantec cert.

When will google decide let's encrypt is not secure enough and start giving a warning around that.

Considering how bad these violations were, and how carefully FF and Chrome are documenting everything, I'd say about never.

Re: Chrome's Plan to Distrust Symantec Certificates

#19
post #3

"including Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL" RIP RapidSSL wildcard

LE Wildcards should be around by then! Hopefully enough tooling will exist to make that migration seamless, or as seamless as cert migration can be.

LE wildcards are coming early 2018 I believe so you'll still have a month or two gap.

Re: Chrome's Plan to Distrust Symantec Certificates

#20

I realize that the title here is what Google put on their blog, but it seems to me that "detrust" would be more accurate than "distrust".

“distrust” is an established English words that means exactly what Google intends. “detrust” is, while not hard to figure out, an unnecessary neologism.

But "distrust" doesn't convey the full meaning. They're not talking about merely not trusting Symantec certificates; they're talking about removing existing trust in the certificates.
Post reply on HN