Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

121–124 of 124 posts

Re: Distrust of Symantec TLS Certificates

#121
post #120

Earlier quoted context omitted.

I understand the rationale behind all of this, but I would get pissed off if Google sent me an email that basically says "do what we tell you to do or we will take your website offline"

That would be bad. It's not what's happening. What's happening is "update your security on the thing that you have already got security on, or else at least two of the most popular browsers will mark it as insecure; also, you will lose points in our search engine".

They are getting close to a monopoly in the browser market and a monopoly in the search market, so yes, this is exactly what's happening. You can pretend it's not a big deal because now they are using their power for good (I guess), but you don't know what they may do next.

Re: Distrust of Symantec TLS Certificates

#122
post #120

Earlier quoted context omitted.

That would be bad. It's not what's happening. What's happening is "update your security on the thing that you have already got security on, or else at least two of the most popular browsers will mark it as insecure; also, you will lose points in our search engine".

They are getting close to a monopoly in the browser market and a monopoly in the search market, so yes, this is exactly what's happening. You can pretend it's not a big deal because now they are using their power for good (I guess), but you don't know what they may do next.

I don't disagree with their existence being a near monopoly at this point.

That said, slippery slopes aren't usually the strongest places from which to wage an argument. We're not talking about what they might do next. We're talking about this specific instance.

Re: Distrust of Symantec TLS Certificates

#123

Earlier quoted context omitted.

I would bat an eye because it's never good to rely on a single point of failure. Imagine, for instance, that at some point, LE is the only trusted CA for code-signing. If its root key gets compromised for some reason, how are we supposed to move to a new CA if the auto-updaters cannot trust the old CA anymore?

True. They should maybe consider breaking up their operation into 20 or so root certs.

As much as I'm tempted to agree, decentralization perhaps risks even more. Opsec compromise is only one SPOF for a signing service; the state might coerce the CA into handing over the keys or issuing an intermediate for MitM.

Do you shard across 20 nations? If so, you have to contend with 20 intelligence agencies. It might make more sense to keep all the eggs in one basket, and have new baskets ready to go if a canary triggers.

Re: Distrust of Symantec TLS Certificates

#124
post #33
post #14

Earlier quoted context omitted.

Symantec should have contacted everyone they issued a certificate to.

It appears that there are a lot of things that Symantec should have done, yet here we are.

Haha it’s so weird, it’s almost like they aren’t very good at being a CA :D
Post reply on HN