Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

21–30 of 124 posts

Re: Distrust of Symantec TLS Certificates

#24

Wow, talk about an obscure warning that tells nothing to the domain owner.

I don't have a copy of Firefox handy to check, but IIRC the message in the inspector is a bit more descriptive.

The message screenshotted in the article is a message to the website visitor, not to the domain owner. And not going out of their way to shame Symantec to every visitor to a site with a Symantec cert is probably a decent policy. Even without their cert business, Symantec is a big player that the browser vendors will have to work with in the future.

Re: Distrust of Symantec TLS Certificates

#25
post #21

Wow, talk about an obscure warning that tells nothing to the domain owner.

Nobody who runs a website can pretend to be ignorant of this fiasco.

I mean with the huge number of set-and-forget Wordpress installations I could absolutely believe people are ignorant of this. I mean why would anyone outside of professional webdevs even care? It's not like this news escaped the tech bubble.

Re: Distrust of Symantec TLS Certificates

#26
post #8

Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

[deleted]

Re: Distrust of Symantec TLS Certificates

#27

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

> Root cause: Symantec was willfully disregarding industry regulations by issuing trusted certificates without proper authorization. Source: https://sslmate.com/certspotter/failures “Willfully” is the key word here. The business side of running a CA is fundamentally at odds with the security side. A few short-sighted decisions by business-minded managers with their eyes set on profits can completely eviscerate the se…

> The business side of running a CA is fundamentally at odds with the security side.

Well, as we're seeing here, they can only be out of phase to a certain degree before both suffer.

Re: Distrust of Symantec TLS Certificates

#28
post #22

Chrome doing likewise: https://security.googleblog.com/2018/03/distrust-of-symantec...

Chrome did this first, so any wide effect (in yall's organsiations) should already have been noticed by now, due to this.

As I understand it, Chrome and Firefox are both operating under the same policies with about the same timetables. Full distrust doesn't come until Firefox 63 / Chrome 70 - neither of which are stable releases yet.

The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.

Re: Distrust of Symantec TLS Certificates

#29
post #18

PayPal's site is affected by this

That's surprising, because Chrome has distrusted Symantec certs for a few months and it's odd that Paypal would not have fixed it by now.

Chrome and Firefox have only distrusted Symantec certs in their pre-release versions. The Chrome 70 and Firefox 63 releases in mid-October are when the hammer will fall.

https://security.googleblog.com/2018/03/distrust-of-symantec...

Post reply on HN