Live data from Hacker News

Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

groups.google.com

271–280 of 329 posts

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#271
post #262

> All Symantec issued certificates. GeoTrust and Thawte are CAs operated by Symantec, simply afforded different branding. >While this list may need to be updated for some recently created roots, https://chromium.googlesource.com/chromium/src/+/master/net/... may accurately capture the state of impact Damn. There goes my certificate (Rapidssl). Anybody know what are the remaining, trustworthy certificate issuers ? No…

DigiCert https://www.digicert.com/ Great company and good people involved in CA/B Forum who advocate on behalf of user security. They'll never pull some of the nonsense the other CA's attempt and I can't recommend them enough. edit: to add, DigiCert were one of the only CA's to support Google's motion to reduce max cert validity period to 12 months, which didn't pass[0] DigiCert were also the CA that helped us get To…

Very cool, thanks for that. Their prices are super super super expensive though.

Almost 10x as expensive as Comodo for wildcard .

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#272

Why not immediately begin treating these connections as plain HTTP? Don't show the padlock or "Secure". Don't fail the connection, so people will still be able to use the site, but don't present it as secure. This would be a stronger action than treating EV certs as non-EV, which only a few geeks will notice. Or reducing the maximum age of certificates.

As someone who just renewed a Symantec EV cert (for a pretty penny), this would super piss me off.

The steps Google has laid out seem proportionate to me. It clearly gets the message across without unduly burdening 3rd parties like me.

And it has nudged me to look at other CAs. Unfortunately the first good option I've looked at--Digicert--has also been publicly rapped on the knuckles by Ryan Sleevi this month.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#273

If anyone here hasn't realised, Symantec bought Verisign back in 2010 - who own many brand names, like GeoTrust, Equifax, Thawte etc. You can see a list of their roots certs here: https://chromium.googlesource.com/chromium/src/+/master/net/... In case you missed it at the bottom: > From Mozilla Firefox’s Telemetry, we know that Symantec issued certificates are responsible for 42% of certificate validations

Wasn't Verisign the very first CA business? How the mighty have fallen!

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#274

Why not immediately begin treating these connections as plain HTTP? Don't show the padlock or "Secure". Don't fail the connection, so people will still be able to use the site, but don't present it as secure. This would be a stronger action than treating EV certs as non-EV, which only a few geeks will notice. Or reducing the maximum age of certificates.

As someone who just renewed a Symantec EV cert (for a pretty penny), this would super piss me off. The steps Google has laid out seem proportionate to me. It clearly gets the message across without unduly burdening 3rd parties like me. And it has nudged me to look at other CAs. Unfortunately the first good option I've looked at--Digicert--has also been publicly rapped on the knuckles by Ryan Sleevi this month.

Pissing off Symantec customers is a necessary evil in this case. It's a sign that the strategy is working.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#275

Earlier quoted context omitted.

> I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? It doesn't. You can adjust your root certs in Firefox by going to about:preferences#advanced and clicking on certificates. But what does partial trust look like? Showing half of the HTML? An eyebrow raised emoji instead of a lock?

I wish CA management was easier to bulk-edit. Show me a table of root CAs with their data, their country of origin, etc., and allow me to filter and enable/disable all based on filters. Full disable would shut down trust entirely, and get the warnings similar to a self-issued cert. Reduced trust would have a "not Secure" label or something, like a plain http connection.

Many CAs are cross-signed, what should the software do in that case?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#276

Why not immediately begin treating these connections as plain HTTP? Don't show the padlock or "Secure". Don't fail the connection, so people will still be able to use the site, but don't present it as secure. This would be a stronger action than treating EV certs as non-EV, which only a few geeks will notice. Or reducing the maximum age of certificates.

And teach your grandpa it's ok if his bank's website no longer displays that green address bar?

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#277
post #50

Earlier quoted context omitted.

ha.ha.ha. I worked at a financial institution for several years. There are many, many IT folks, internal auditors, and others who are probably wishing they wore their brown pants to work today. SSL certificates are cheap in contrast to the labour intensive management practices that exist around them, especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I…

>especially around legacy platforms that may have been hardcoded to use certificates from a specific issuer (not that I have ever seen that before, no one would be that foolish right? :/) D'ya know, I would have naively assumed this wasn't technically possible. I shudder not only to think of the code, but also of the thought process that could compel someone to undergo the effort of bricking themselves into this corn…

A number of people recommend doing that as best practice.

https://raymii.org/s/articles/HTTP_Public_Key_Pinning_Extens...

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#278
post #3
post #2

This is huge, Symantec owns about 15% of the SSL certificate market[1], and as stated in the article, has issued 30% of in-use certificates. No certificate authority of this size has ever been raked over the coals like this. [1] https://w3techs.com/technologies/history_overview/ssl_certif...

Pretty much it will decide the question on whether or not the certificate system is even workable. My thesis is that either Symantec will not be able to respond (and so lose their ability to be a root certificate) in which case it will warn other root cert authorities to shape up or lose their business, or they will placate the Google and Chromium teams somehow and show that root cert authorities can be brought to be…

Maybe, but in the meantime I can't imagine a scenario where such a direct financial threat to a business isn't vigorously defended by Symantec. I'm not a lawyer, but certainly they must be working to determine if they have a legal basis for seeking an injunction against Google. They could even be building some sort of legal theory based on tortious business interference, contending that Google is doing irreparable harm by trying to come between Symantec and the expectations of its paying customers.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#279
post #27

Earlier quoted context omitted.

> Or they will ignore Google, continue to create bad certs, and users will start getting instructed by sites that they have to manually add a root certificate in order to use they site, and the entire ecosystem will collapse. IIRC that's Amazon's answer to 'how should a user install Amazon Prime on Android?' I don't know how successful they've been convincing users to allow installation of untrusted apps (I certainly…

Installing apps from other stores on Android is literally a checkbox away - but installing new root certs on computers is considerably harder, or impossible if your computer is locked-down (group policy, etc).

Installing new roots on Macs, iOS, and Android devices is really easy. It's mildly inconvenient on Linux desktops.

Re: Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates

#280
post #255

Earlier quoted context omitted.

> I've often wondered: why is trust in CAs an all-or-nothing proposition (aside from EV certs), and why should my particular browser vendor have all the authority over who I should trust? It doesn't. You can adjust your root certs in Firefox by going to about:preferences#advanced and clicking on certificates. But what does partial trust look like? Showing half of the HTML? An eyebrow raised emoji instead of a lock?

I could go for an eyebrow-raised emoji in some cases. Self-signed certs for instance, or any root cert that the browser picks up from the OS.

Is there an eavesdropper emoji?
Post reply on HN