Earlier quoted context omitted.
Interesting point. I spot checked CAs for some of the most popular USA government websites. irs.gov (Internal Revenue Service): Entrust CA va.gov (Veterans Affairs) : Symantec CA So if Symantec is the CA for a critical mass of government websites that won't abandon them, Google Chrome could lose this battle. Without looking at traffic data (e.g Alexa), my intuition says the vast majority of web traffic is not governm…
I believe it is actually a matter of political campaigning in South Korea to get rid of ancient IE ActiveX requirements for government websites.
Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
211–220 of 329 posts
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#212https://knowledge.symantec.com/support/ssl-certificates-supp...
(Archive link: http://archive.is/Cq9VO )
Really interesting reading!
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#213We need a service to check if your certs could be flagged as bad. Especially since this spans so many brands (Symantec, Equifax, VeriSign, GeoTrust, Thawte, etc). Something like, plug in the domain name, and it'll tell you if you need to update the cert.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#214Earlier quoted context omitted.
Oh no, of the 20 users that know about EV, 2 might send an email.
EV actually causes a different "secure" UI to display in the browser. Usually it is the name of the corporate entity that the certificate is issued for. If you don't have EV you only get a padlock.
I think there are groups of smart PKI/UI people discussing how better to design security warnings at various levels of EV/HTTPS/Partial HTTPS/HTTP.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#215Earlier quoted context omitted.
ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…
Well, you guys here love capitalism, and this is capitalism. If you make such astonishingly obviously poor decisions, you deserve to fail.
And market consumers lack the technical ability to discriminate between anything more finely grained than "works" / "doesn't work."
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#216Earlier quoted context omitted.
Am I the only one worried about LetsEncrypt becoming a monopoly? This move from Google is, indirectly, a huge service for them.
If I'm reading the settings page right, Chrome trusts over 70 certificate issuers right now. Let's Encrypt is just one of those, and only issues a limited set of certificate types.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#217I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? For the vast majority of users that's probably just fine, but I would have thought that there'd be a browser or extension or something that allows security-conscious power users more fine-grained control over this by now. For example,…
> I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? It doesn't. You can adjust your root certs in Firefox by going to about:preferences#advanced and clicking on certificates. But what does partial trust look like? Showing half of the HTML? An eyebrow raised emoji instead of a lock?
Full trust: green lock icon
Medium trust: yellow lock icon with list of reasons when clicked
Low trust: prompt when attempting to load
No trust: completely blocked, or more difficult to override (like Chrome does now)
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#218Earlier quoted context omitted.
Also wondering this, as I'm about to buy a new cert.
I switched to DIGICERT when Verisign started buying everyone up (then Symantec bought them). I haven't looked back...except for dev boxes where I can get away with Let's Encrypt. For business I highly recommend DIGICERT. They are an independent company.
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#219Earlier quoted context omitted.
Banks and companies like First Data were the (sole?) source of exception requests for SHA-1 issuance past the date it was prohibited. Given the G1 root they pulled has an intermediary called "Symantec Trust Services Private SHA1 Root CA", I can make some guesses...
The exception process used by payment processors such as First Data were for SHA-1 certificates chaining to a root that was still publicly-trusted. They couldn't use an off-reservation root because their client devices didn't trust them. The roots that Symantec took off-reservation are regularly issuing SHA-1 certificates to anyone whose check clears. Got $1,699 to spare? https://www.thesslstore.com/symantec/secure-s…
Side note: Are payment systems required to link to revalidate their roots at any regular intervals?
Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
#220Earlier quoted context omitted.
This is a good summary, but I'd clarify it by saying that Google isn't being subjective about Symantec's process failures. The CA industry self-regulates. Its regulatory organization is the CA/B Forum, and their principal regulation is the Baseline Requirements (the BRs). Google claims Symantec violated multiple BRs. If you want to dig a little deeper, here's the last version of the BRs: https://cabforum.org/wp-conte…
Small correction: the CA industry doesn't self-regulate. Both browsers and CAs participate in the CA/Browser Forum and my (admittedly outsider) impression is that browsers almost always have the upper hand.