Earlier quoted context omitted.
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
21–30 of 118 posts
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#22This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…
So why doesn't Blue Coat establish their own CA for this purpose?
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#23This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#24Earlier quoted context omitted.
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…
Even that is silly - they don't need to be an intermediate CA to do that. Just require that their customers install a custom certificate.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#25Earlier quoted context omitted.
If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.
Sure - but from the (to be taken with appropriate credibility rating) WikiPedia page for BlueCoat: "Blue Coat products are primarily used by enterprises, schools, hospitals, governments, and public agencies to block malware and malicious threats, control access to applications and content in the workplace, surveillance, censorship, and improve the performance of network applications." I'm resigned to acknowledging th…
A good number of employer or school-provider devices will have their own certificates preinstalled anyway.
Nobody ever said privacy was convenient.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#26Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#27I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…
They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#28So, how much of my internet will break if I distrust the Symantec cert on my machine?
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#29This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…
I'm hesitant to relax here. Blue Coat's got a nasty history of making money off of the regimes that'd do this without hesitation: https://www.newsrecord.co/us-based-internet-surveillance-tec...
If Symantec didn't revoke the certificate then it would almost certainly lead to their root certificate being untrusted by major browsers and destroy their entire certificate business.