Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

111–120 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#111
post #90

Earlier quoted context omitted.

Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc. I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.

What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.

Wouldn't you say it would be enough to pin those certs to TLDs?

Re: Chrome's Plan to Distrust Symantec Certificates

#112
post #111
post #90

Earlier quoted context omitted.

What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.

Wouldn't you say it would be enough to pin those certs to TLDs?

By TLD do you mean country domains?

Then absolutely not. Why should a US company not be allowed to use a Swiss-issued certificate for a .io domain name?

Re: Chrome's Plan to Distrust Symantec Certificates

#113
post #106

Earlier quoted context omitted.

https://certsimple.com It’s incredibly fast, the guy who runs it is nice, great customer service. It just does what you need.

Thanks James! Mike from CertSimple here. HN folk can give me a shout anytime (mike@certsimple.com) or ask here - it's midnight in the UK but I'll be back up in the morn!

I believe that EV certificates cannot be wildcard certs, is this still true?

Re: Chrome's Plan to Distrust Symantec Certificates

#114
post #106

Earlier quoted context omitted.

Thanks James! Mike from CertSimple here. HN folk can give me a shout anytime (mike@certsimple.com) or ask here - it's midnight in the UK but I'll be back up in the morn!

I believe that EV certificates cannot be wildcard certs, is this still true?

yes.

Re: Chrome's Plan to Distrust Symantec Certificates

#115

What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…

I'm unfamiliar with the problem space. What are some of the use-cases for EV certificates?

It looks like lots of big name sites don't use them. Why do some companies feel they need it, while letting internet giants such as Facebook, Google, Microsoft, etc. get away without it?

Re: Chrome's Plan to Distrust Symantec Certificates

#116

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…

> The user should be the one controlling the list of trusted CAs and servers, not a third party such as ad-supported company or organization distributing a web browser.

No, they really shouldn't. Security is a ridiculously complex arena, and the amount of knowledge you need to make an intelligent setup on this is considerable. For tech-heads, fine, but the vast majority of people are not tech-heads.

If you switched over to this model, we'd end up in the bad old days of Windows XP, where untrained people would advise untrained people to 'just install this package and everything works!' and half the time they'd be installing malware. The right way to do this is 'sensible defaults, that the user can adjust'.

Re: Chrome's Plan to Distrust Symantec Certificates

#117
post #4

If you are using the free SSL provided your Webhost "Let's Encrypt" certificate, you will be fine. That is not a Symantec cert.

When will google decide let's encrypt is not secure enough and start giving a warning around that.

for a decentralized web - a way for people to be compensated for their time - mesh network - decentralized dns market - reservation system that supports known brands keeping their name - allows enough fluctuations that a name can be rereserved - opensource browser - keeping it simple enough for newbies to figure it out - a way to associate a public key to an IP address, reverify it and legitimize it - p2p shared files - trackers/dht torrent - decentralized hueristics - timelimit, algorithm fn, score fn, prize for heighest score

Re: Chrome's Plan to Distrust Symantec Certificates

#118
post #90

Earlier quoted context omitted.

What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.

Is it unreasonable to expect a foreign ecommerce site to use a CA that it's users can trust?

You're right. Americans should discard Turkish and Chinese CAs in favour of one homed in the heart of their tech capital in Silicon Valley. Clearly those foreign ones are shysters and not to be trusted like a locally-built, trustworthy business!

Oh, what's that? Symantec is an American company, headquartered in Mountain View, CA?

Re: Chrome's Plan to Distrust Symantec Certificates

#119
post #106

Earlier quoted context omitted.

Thanks James! Mike from CertSimple here. HN folk can give me a shout anytime (mike@certsimple.com) or ask here - it's midnight in the UK but I'll be back up in the morn!

I believe that EV certificates cannot be wildcard certs, is this still true?

Yep, what @detaro said. Here's the specifics: https://certsimple.com/blog/wildcard-ev-certificate

Re: Chrome's Plan to Distrust Symantec Certificates

#120
post #104
post #102

Earlier quoted context omitted.

For all reasonable adversary examples shy of panopticon, downloading from multiple physical sites and global proxies and comparing the same roots across downloads should be sufficient, no?

Ohhhh gotcha, seems legit. I thought the certs in step 3 were individual site certs, not the roots. Thought he was going for some site-level pinning or something.

[deleted]
Post reply on HN