Live data from Hacker News

DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

investor.symantec.com

51–59 of 59 posts

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#51
post #45

Earlier quoted context omitted.

I'm really having trouble following you. You keep writing as if the alternative to Digicert's fire-sale acquisition was that Symantec's CA would simply vanish off the face of the Earth. No. False premise.

Please explain. If their certs become useless and no-one will touch them because, in turn, their certs will be useless... then how wouldn't Symantec's CA vanish off the face of the earth? Their customers can't exactly live without the PKI -- they would just have to go to another vendor, as they should in any case. If those customers have made poor engineering decisions in their own products, well, that's their proble…

I think you've oversimplified the pre-existing Google/Mozilla distrust plan, and your misapprehension about what was happening has harmed your understanding of the economics of this acquisition.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#52
post #51

Earlier quoted context omitted.

Please explain. If their certs become useless and no-one will touch them because, in turn, their certs will be useless... then how wouldn't Symantec's CA vanish off the face of the earth? Their customers can't exactly live without the PKI -- they would just have to go to another vendor, as they should in any case. If those customers have made poor engineering decisions in their own products, well, that's their proble…

I think you've oversimplified the pre-existing Google/Mozilla distrust plan, and your misapprehension about what was happening has harmed your understanding of the economics of this acquisition.

You're right. I probably do need to go back and re-examine the details. Generally when disagreements happen, one or both parties is missing something. At the same time, I still feel this is far too nice an ending for Symantec given the shit they pulled.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#53

Earlier quoted context omitted.

They should have been utterly destroyed; not parted out to the highest bidder. I want every Symantec shareholder to feel the pain of a zero share price for what they enabled.

The point I'm trying to make is that they're not dead if they own 30% of digicert as a result of this instead of being left with nothing.

It's hard to put a value on the deal [1]. But -

Using the rankings of CA's largest to smallest [2], the first public CA is GoDaddy (W2Techs 2016 Survey), which has a range of services. They show GoDaddy to be 11.8% of the market, with Symantec at 26%. So Symantec is 220% larger. I'm too lazy to estimate GoDaddy's CA business from their financials, I didn't see anything obvious in their financials to make it easier.

GoDaddy's public valuation at this time is 7.27B [3], and if we scale up GoDaddy Market Cap to Symantec's size, and only account 20% [4] to the CA business: 7.27B * (26/11.8) * .2 = ~3.2B (Symantic CA Business)

If we use DigiCert, and try to GoDaddy's market cap down to DigiCerts market share (3.0%) [2]. Then you end up with 7.27B * (3.0/11.8) * .2 = ~370M (DigiCert Current Valuation)

However, DigiCert becomes number two CA provider overnight, to 29%, which rockets their value up (maybe?), by our same math, they are now 245% the size of GoDaddy from a cert perspective, 7.27B * ((26 + 3)/11.8) * .2 = ~3.57B (DigiCert + Symantec Business) [5].

So Symantec ends up with 950m cash and 1.07B DigiCert holdings (3.57B * .3 = 1.07B), or ~1.957B of value.

That'd mean Symantec is taking 2/3rds (~1b hit) - that feels like a pretty solid deterrent?

1. Armchair economist 2. https://en.wikipedia.org/wiki/Certificate_authority 3. https://www.google.com/finance?q=NYSE%3AGDDY&ei=qU-CWciuPMqg... (8/2/2017 EOD MarketCap) 4. This could be wildly high.. 5. Normally a combined entity would have duplicative operations and arguably be worth more than their whole, but since these are kind of iffy assets, they probably would be worth less.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#54
post #49

Earlier quoted context omitted.

With 30% control, you can bet there are Symantec CA business people coming into Digicert.

Would you like to make that bet more explicit? I would be game.

Sure. How would we judge it though?

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#55
post #45

Earlier quoted context omitted.

I'm really having trouble following you. You keep writing as if the alternative to Digicert's fire-sale acquisition was that Symantec's CA would simply vanish off the face of the Earth. No. False premise.

Please explain. If their certs become useless and no-one will touch them because, in turn, their certs will be useless... then how wouldn't Symantec's CA vanish off the face of the earth? Their customers can't exactly live without the PKI -- they would just have to go to another vendor, as they should in any case. If those customers have made poor engineering decisions in their own products, well, that's their proble…

I think the discussion you and tptacek are having relates, in a way, to how different people approach the criminal justice system. People generally want it to either punish the guilty (Watchmen's Rorschach) or protect the innocent (Sweden), and I think Symantec's dissolution looks like a carefully thought out plan to protect the innocent.

Badness happened, but no more. There are paths forward for everyone involved. No more harm, just move forward.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#56
post #11

Presumably the idea here is that DigiCert is buying Symantec's customer database, and instead of Symantec painstakingly transferring its users to a new, trustworthy certificate issuance system, everyone will just use DigiCert's. Which, if that's the case, will mean Google and Mozilla more or less killed the web's largest CA.

Symantec killed their own CA with their misdeeds. Google and Mozilla just carried the bullet a while.

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#57
post #49

Earlier quoted context omitted.

Would you like to make that bet more explicit? I would be game.

Sure. How would we judge it though?

Lay out the scenario, in as much detail as you can, where employees of Symantec brought over to DigiCert somehow corrupt the certificate issuance process. If it's specific enough, I'll take your money over it (I assume proceeds to charity; mine's Partners In Health).

Re: DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

#59
post #7

How is Symantec's cert business not a toxic asset given their historical practices?

Oh, it's almost certainly a toxic asset.

But have you seen the blog post where Symantec was like "We talked to our customers and they said that Google's being mean"? https://www.symantec.com/connect/blogs/symantec-ca-proposal

> Many large organizations have complex, and potentially undocumented and little-known dependencies on their certificate infrastructure. Examples of complex dependencies on Symantec public roots that our customers have shared or we have identified include:

> Embedded devices that are pinned to certificates issued by a Symantec public root to communicate to resources over the Internet or Intranet. Replacing these certificates would result in immediate failures and the need to recode and reimage the firmware for these devices.

> Mobile applications that have pinned certificates. Replacing server certificates would require these applications to be recoded, recompiled and redistributed.

> Critical infrastructure organizations that use certificates issued off of Symantec roots to validate internal and external resources. In many cases, the applications being used are pinned to Symantec certificates.

> Some large organizations use certificates chained to Symantec public roots for nearly all internal applications and communications. Many of these organizations are under regulatory requirements to encrypt even internal communications.

You have lots of customers that have made the stupid decision to hard-code the Symantec public key as indefinitely trustworthy. (Some of them may well have got Symantec to do the consulting for their internal infrastructure.) No matter how stupid the decision is, it's been made, and those customers will pay good money for a cert that's either issued directly from or chains to the Symantec root.

Even if the only thing that DigiCert does with the Symantec private key is to sign their own CA and then destroy it, and they kill the Symantec brand and every piece of Symantec infrastructure, that still brings them tons of customers who literally cannot move to a competitor not in possession of the Symantec private key. I'm not surprised that's worth $1B.

Post reply on HN