Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

31–40 of 124 posts

Re: Distrust of Symantec TLS Certificates

#32
post #9

Earlier quoted context omitted.

I've wondered the same. Certificate trust was absolutely crucial to their business. The only thing I can think is that the leadership was oblivious to this. Maybe they didn't understand how certificates work.

Sell more certificates, make more money. Anything which gets in the way of making more money (like security) should be reduced or eliminated, with the right touch you can get bonuses / promotions for meeting fiscal goals and leave your successor to deal with the aftermath. They might understand how certificates work but that doesn’t mean they know how to set up an organization with the right incentives to do it corre…

Interestingly, I looked up the symantec CEO. He was previously the ceo of Blue Coat. Blue Coat is a maker of man in the middle proxy appliances for businesses to spy on their employees. They controversially got root certificate authority. Which could of course be used to mitm SSL sites (which they promised and crossed their heart they would never do).

https://www.theregister.co.uk/2016/05/27/blue_coat_ca_certs/

Re: Distrust of Symantec TLS Certificates

#33
post #14

Wow, talk about an obscure warning that tells nothing to the domain owner.

Symantec should have contacted everyone they issued a certificate to.

It appears that there are a lot of things that Symantec should have done, yet here we are.

Re: Distrust of Symantec TLS Certificates

#34

Chrome doing likewise: https://security.googleblog.com/2018/03/distrust-of-symantec...

Apple¹ and Mircosoft² are doing the same. Additionally anything that uses Chromium's trustlists (Vivaldi, Electron, etc) will also distrust old Symantec & co's certs.

1: https://support.apple.com/en-us/HT208860 2: https://knowledge.digicert.com/alerts/ALERT2562.html

EDIT: Its also worth mentioning that this isn't just limited Symantec certs but also will include GeoTrust, thawte, & VeriSign certs. Symantec's cert business has now been taken over by DigiCert so there is a means for valid reassurance.

EDIT2: Also it will effect RapidSSL. Totally forgot about them.

Re: Distrust of Symantec TLS Certificates

#35
post #19

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

The problem is that they repeatedly mismanaged and violated the BRs. There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA. Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA…

Pardon my ignorance, but what does "BR" stand for?

Re: Distrust of Symantec TLS Certificates

#36

It would be nice to have the date reflected in the title of this post (March 2018). It's relevant and a nice reminder because the full-distrust is coming soon, but there isn't anything new here AFAICT.

Right, nothing new here. I was confused when I read the title, thinking "it was already distrusted, is there some further amount of distrust possible or is it groundhog day?"

Re: Distrust of Symantec TLS Certificates

#37
post #8

Wow, I didn't realise how many non-conformances there were with Symantec. It certainly looks like they had enough chances to get their houses in order and didn't! I wonder what the root problem was? They didn't care, they didn't think anyone would do anything or they are just a large sloppy corporate who can't run a group properly?

My impression: For years it was common practice that when CAs messed something up it would cause some complains, but no real consequences. The large CAs thought they were "too big to fail". They thought it would just go on like that. They (and many others in the industry) didn't believe that Google was serious when they threatened with browser removal. When they realized Google was serious it was too late to change their course.

Re: Distrust of Symantec TLS Certificates

#38
This is huge as it affects GeoTrust, RapidSSL, Thawte, and VeriSign.

I was aware of the Symantec issue and checked my own certs and didn't see their name, but skimming the article I noticed RapidSSL and thought I'd double check and sure enough my certs are about to become bogus.

Re: Distrust of Symantec TLS Certificates

#39
post #21

Wow, talk about an obscure warning that tells nothing to the domain owner.

Nobody who runs a website can pretend to be ignorant of this fiasco.

I knew that my sites weren't at risk because I don't have Symantec certs. It was only triple checking things today that I discovered RapidSSL is a Symantec cert and I am in fact affected.

Re: Distrust of Symantec TLS Certificates

#40
post #19

Earlier quoted context omitted.

The problem is that they repeatedly mismanaged and violated the BRs. There’s only so many screw ups you can accept from a CA before you simply can’t trust them to do the right thing. Given that Trust is the basis of the entire CA system there isn’t really an option but to distrust the CA. Note that multiple CAs have been distrusted in the past, and they were more or less instantaneous distrust. Symantec was a huge CA…

Pardon my ignorance, but what does "BR" stand for?

Pretty sure it refers to "Baseline Requirements" as specified by the CA Browser Forum.

https://en.m.wikipedia.org/wiki/CA/Browser_Forum

Post reply on HN