Earlier quoted context omitted.
I'm really having trouble following you. You keep writing as if the alternative to Digicert's fire-sale acquisition was that Symantec's CA would simply vanish off the face of the Earth. No. False premise.
Please explain. If their certs become useless and no-one will touch them because, in turn, their certs will be useless... then how wouldn't Symantec's CA vanish off the face of the earth? Their customers can't exactly live without the PKI -- they would just have to go to another vendor, as they should in any case. If those customers have made poor engineering decisions in their own products, well, that's their proble…
DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
51–59 of 59 posts
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#52Earlier quoted context omitted.
Please explain. If their certs become useless and no-one will touch them because, in turn, their certs will be useless... then how wouldn't Symantec's CA vanish off the face of the earth? Their customers can't exactly live without the PKI -- they would just have to go to another vendor, as they should in any case. If those customers have made poor engineering decisions in their own products, well, that's their proble…
I think you've oversimplified the pre-existing Google/Mozilla distrust plan, and your misapprehension about what was happening has harmed your understanding of the economics of this acquisition.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#53Earlier quoted context omitted.
They should have been utterly destroyed; not parted out to the highest bidder. I want every Symantec shareholder to feel the pain of a zero share price for what they enabled.
The point I'm trying to make is that they're not dead if they own 30% of digicert as a result of this instead of being left with nothing.
Using the rankings of CA's largest to smallest [2], the first public CA is GoDaddy (W2Techs 2016 Survey), which has a range of services. They show GoDaddy to be 11.8% of the market, with Symantec at 26%. So Symantec is 220% larger. I'm too lazy to estimate GoDaddy's CA business from their financials, I didn't see anything obvious in their financials to make it easier.
GoDaddy's public valuation at this time is 7.27B [3], and if we scale up GoDaddy Market Cap to Symantec's size, and only account 20% [4] to the CA business: 7.27B * (26/11.8) * .2 = ~3.2B (Symantic CA Business)
If we use DigiCert, and try to GoDaddy's market cap down to DigiCerts market share (3.0%) [2]. Then you end up with 7.27B * (3.0/11.8) * .2 = ~370M (DigiCert Current Valuation)
However, DigiCert becomes number two CA provider overnight, to 29%, which rockets their value up (maybe?), by our same math, they are now 245% the size of GoDaddy from a cert perspective, 7.27B * ((26 + 3)/11.8) * .2 = ~3.57B (DigiCert + Symantec Business) [5].
So Symantec ends up with 950m cash and 1.07B DigiCert holdings (3.57B * .3 = 1.07B), or ~1.957B of value.
That'd mean Symantec is taking 2/3rds (~1b hit) - that feels like a pretty solid deterrent?
1. Armchair economist 2. https://en.wikipedia.org/wiki/Certificate_authority 3. https://www.google.com/finance?q=NYSE%3AGDDY&ei=qU-CWciuPMqg... (8/2/2017 EOD MarketCap) 4. This could be wildly high.. 5. Normally a combined entity would have duplicative operations and arguably be worth more than their whole, but since these are kind of iffy assets, they probably would be worth less.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#54Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#55Earlier quoted context omitted.
I'm really having trouble following you. You keep writing as if the alternative to Digicert's fire-sale acquisition was that Symantec's CA would simply vanish off the face of the Earth. No. False premise.
Please explain. If their certs become useless and no-one will touch them because, in turn, their certs will be useless... then how wouldn't Symantec's CA vanish off the face of the earth? Their customers can't exactly live without the PKI -- they would just have to go to another vendor, as they should in any case. If those customers have made poor engineering decisions in their own products, well, that's their proble…
Badness happened, but no more. There are paths forward for everyone involved. No more harm, just move forward.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#56Presumably the idea here is that DigiCert is buying Symantec's customer database, and instead of Symantec painstakingly transferring its users to a new, trustworthy certificate issuance system, everyone will just use DigiCert's. Which, if that's the case, will mean Google and Mozilla more or less killed the web's largest CA.
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#57Earlier quoted context omitted.
Would you like to make that bet more explicit? I would be game.
Sure. How would we judge it though?
Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#58Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
#59How is Symantec's cert business not a toxic asset given their historical practices?
But have you seen the blog post where Symantec was like "We talked to our customers and they said that Google's being mean"? https://www.symantec.com/connect/blogs/symantec-ca-proposal
> Many large organizations have complex, and potentially undocumented and little-known dependencies on their certificate infrastructure. Examples of complex dependencies on Symantec public roots that our customers have shared or we have identified include:
> Embedded devices that are pinned to certificates issued by a Symantec public root to communicate to resources over the Internet or Intranet. Replacing these certificates would result in immediate failures and the need to recode and reimage the firmware for these devices.
> Mobile applications that have pinned certificates. Replacing server certificates would require these applications to be recoded, recompiled and redistributed.
> Critical infrastructure organizations that use certificates issued off of Symantec roots to validate internal and external resources. In many cases, the applications being used are pinned to Symantec certificates.
> Some large organizations use certificates chained to Symantec public roots for nearly all internal applications and communications. Many of these organizations are under regulatory requirements to encrypt even internal communications.
You have lots of customers that have made the stupid decision to hard-code the Symantec public key as indefinitely trustworthy. (Some of them may well have got Symantec to do the consulting for their internal infrastructure.) No matter how stupid the decision is, it's been made, and those customers will pay good money for a cert that's either issued directly from or chains to the Symantec root.
Even if the only thing that DigiCert does with the Symantec private key is to sign their own CA and then destroy it, and they kill the Symantec brand and every piece of Symantec infrastructure, that still brings them tons of customers who literally cannot move to a competitor not in possession of the Symantec private key. I'm not surprised that's worth $1B.