Earlier quoted context omitted.
You seem to be conflating expectations and reality. They did kill the business, but Symantec was able to salvage part of it.
They should have been utterly destroyed; not parted out to the highest bidder. I want every Symantec shareholder to feel the pain of a zero share price for what they enabled.
DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
31–40 of 59 posts
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#32How is Symantec's cert business not a toxic asset given their historical practices?
But I'm sure it'll go right back to printing money once it's no longer directly associated with a vendor of TLS interception middle boxes popular among despots. And the browser relations fiasco will blow over eventually.
Might cost them a bunch of rebates and refunds to keep clients, but I see why this could be a viable customer acquisition move for DigiCert.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#33Earlier quoted context omitted.
They should have been utterly destroyed; not parted out to the highest bidder. I want every Symantec shareholder to feel the pain of a zero share price for what they enabled.
The point I'm trying to make is that they're not dead if they own 30% of digicert as a result of this instead of being left with nothing.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#34Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#35Earlier quoted context omitted.
It's Symantec's past operation of the CA that's untrusted by Google, and in fact one of the proposals was that Symantec make a new CA and cross-sign it with their old one, which would maintain compatibility for previous customers that pinned the Symantec root as well as customers using up-to-date browsers. So if the setup here is that DigiCert signs their own CA with Symantec's, then everyone's happy: DigiCert gets t…
I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#36I'm a reseller for Digicert - they just sent an announcement email about this, here's the most interesting bit: "Earlier this year, the browsers proposed a plan to limit trust in Symantec certificates after discovering issues with how they were validating and issuing digital certificates. Importantly, we feel confident that this agreement will satisfy the needs of the browser community. DigiCert is communicating this…
You may want to come up with an escape plan then. If digicert can buy Symantec so that Symantec can escape censure what message does that send? At this point Symantec should be considered so radioactive that nobody would go near it for fear of contamination. Symantec betrayed all of us and digicert, in buying it and rewarding the behaviour is doing the same.
However, I don't think that anyone is actually going to make Symantec as contaminated as you or I want. If the people at DigiCert who were competent yesterday are operating Symantec's infrastructure today, that infrastructure is now trustworthy. And in buying and salvaging it, DigiCert did the community a service: instead of leaving us in this ambiguous position where a too-big-to-fail CA was calling up Google executives to potentially overrule engineering decisions, that CA is now no longer a threat.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#37Earlier quoted context omitted.
I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.
The checkboxes you're implicating here are the ceremonial kind. (I do security in the financial infrastructure space, for whatever that's worth).
Whether it's ceremony or not, I have to check the box or face harsh regulatory penalties.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#38Earlier quoted context omitted.
It's Symantec's past operation of the CA that's untrusted by Google, and in fact one of the proposals was that Symantec make a new CA and cross-sign it with their old one, which would maintain compatibility for previous customers that pinned the Symantec root as well as customers using up-to-date browsers. So if the setup here is that DigiCert signs their own CA with Symantec's, then everyone's happy: DigiCert gets t…
I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.
You have a perfectly valid reason, which is that your auditors want you to buy an expensive certificate to make them happy, but you're still paying more than market ($0ish) for SSL, which means you're a good customer for DigiCert to have acquired.
BTW, if you want to save some money, try sending your auditors the WebTrust audits that Let's Encrypt has passed just as well as Symantec (if not more well, see mozilla.dev.security.policy): https://letsencrypt.org/repository/
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#39Earlier quoted context omitted.
I work in the financial infrastructure space, and while I'm no fan of Symantec, using Let's Encrypt would get me laughed out of the room by compliance and our auditors. Some checkboxes are ceremony, some have real purpose. One size does not fit all.
I suspect your auditors have no real reason to object to Let's Encrypt (do they understand that Let's Encrypt is equally capable of issuing a false certificate under your name? does your security rely on the browser PKI? how did every single company in the browser PKI get okayed by your auditors?). You have a perfectly valid reason, which is that your auditors want you to buy an expensive certificate to make them hap…
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#40How is Symantec's cert business not a toxic asset given their historical practices?