Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

61–70 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#61
TL;TR: Don't get wild for no reason. Take instead a look at the certificate. pathlen=0

I doubt that this certificate will be used on BlueCoat appliances to MITM connections. It has a pathlen of 0 which means that it can be used to sign leaf certificates (i.e. for servers) but it cannot be used to create an additional CA. Thus in order to use this CA certificate for MITM on BlueCoat devices BlueCoat would install this certificate including its private key on all BlueCoat devices which would quickly expose the private key to the public.

I think that this certificate is more used inside BlueCoat's own infrastructure, i.e. to sign their companies certificates. This would be similar to what Google and others do for a long time already. And with a similar setup, i.e. "Google Internet Authority G2" has also a pathlen=0.

(this is a copy of my post on reddit/r/netsec).

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#62

Earlier quoted context omitted.

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Even Cloudflare doesn't use their own CA, but they have a relationship with Comodo; at least, from what I can tell on services I use with Cloudflare. If they just need to issue lots of certificates, or make it easy for client devices to get certificates, or even for their own cloud services, they could use LetsEncrypt. There are very few use cases where having your own CA is necessary, and for a company like Blue Coa…

This is insane, like you said even CloudFlare isn't a CA.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#63
post #53
post #15

Earlier quoted context omitted.

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

I don't see the legitimate use case here. If they're dealing with inbound TLS connections to their cloud services then they can scan or modify the traffic on the cleartext side of the TLS connection. No need to be a CA. If they have clients on their network they want to MITM then that's not a legitimate use case for a CA at all. It doesn't matter if everything is on their network, it's unacceptable that my browser ac…

They needed the excuse to become a ca. Now they can mitm in third world countries

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#64
post #11

I wonder just how many certs I'd notice failing if I pulled Symantec's root out of my keystore - and if I'd get any mileage contacting the sites that end up broken and explaining why. This is exactly the sort of thing I'd like to have the "CA death penalty" seriously considered against Symantec - but I fear they're going to be judged "too big to fail". A grass roots campaign of contacting sites (especially sites I've…

What I would really like to see is a curated list of CAs and intermediates instead of the huge list my browser currently trusts. Preferably a browser extension like EFF's Privacy Badger, to make it easier to use.

I have gone into Firefox's settings and deleted random certs like the Hong Kong Post Office and this didn't break any of the sites I use, but all certificates are re-installed each time Firefox updates.

Thinking more globally, someone living in Hong Kong might prefer to keep the Post Office one but distrust all American CA's from their browser and they should be accommodated too.

Imagine treating the set of trusted CAs in your browser just like your ad blocker's filter list. You would damn sure need a trustworthy curator to maintain that list, but it seems doable (in my admittedly non-expert and humble opinion). Does such a thing exist? Moxie's Convergence extension is the closest thing to it that I'm aware of: https://en.wikipedia.org/wiki/Convergence_%28SSL%29

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#65
post #43

You know, the main job for a web CA is to verify the owner of a domain. What if... domain registrars had that job instead? They definitively know the domain registrant, no need to play games with email verification tokens or http challenges.

Domain registries & registrars do not generally verify the identity of the registrant. It can occur, but only if trademark protection mechanisms are invoked.

By testing the DNS, you really verify the domain operator, which in practice means anyone who can update the NS/DS/glue records. It's arguably quite a weak assertion.

Similarly this explains why DV certificates are cheap and EV certificates are less cheap.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#66
post #35

Earlier quoted context omitted.

I'm unclear about what you're saying. Are you saying it is OK for them to MITM traffic to https://google.com on their network by issuing a google.com cert? That is definitely not OK. If they only issue certs for domains that belong to themselves or their customers, that is OK.

Notwithstanding key pinning (which I believe is even overridden by installed private roots), they can issue for google.com as long as they want so long as they get their users to install a private root.

This, MITM using voluntarily installed trust anchors is one thing and explicitly allowed by google, creating a certificate for google.com that will be accepts by all TLS clients is not and Symantec have got in trouble before for doing this.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#67

TL;TR: Don't get wild for no reason. Take instead a look at the certificate. pathlen=0 I doubt that this certificate will be used on BlueCoat appliances to MITM connections. It has a pathlen of 0 which means that it can be used to sign leaf certificates (i.e. for servers) but it cannot be used to create an additional CA. Thus in order to use this CA certificate for MITM on BlueCoat devices BlueCoat would install this…

not true, bluecoat devices could simply ask a bluecoat server with the CA for arbitrary certs.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#68

TL;TR: Don't get wild for no reason. Take instead a look at the certificate. pathlen=0 I doubt that this certificate will be used on BlueCoat appliances to MITM connections. It has a pathlen of 0 which means that it can be used to sign leaf certificates (i.e. for servers) but it cannot be used to create an additional CA. Thus in order to use this CA certificate for MITM on BlueCoat devices BlueCoat would install this…

> Thus in order to use this CA certificate for MITM on BlueCoat devices BlueCoat would install this certificate including its private key on all BlueCoat devices which would quickly expose the private key to the public.

They can simply expose a cert issuing service over the internet.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#69
post #14

This isn't necessarily as nefarious as it seems - Blue Coat is going to have to comply with Symantec's Certification Practice Statement(CPS) which prohibits the issuance of MitM certificates. In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. Th…

You're making a lot of assumptions about the terms under which this certificate was issued, which you don't know. Without seeing the contract between Symantec and Blue Coat you can't claim that they're bound by Symantec's CPS.

And even if they are bound by Symantec's CPS, they can do a lot of damage before the CPS can be enforced.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#70

I'm posting this because within the past year, Symantec has gotten in hot water for issuing rogue certificates[1]. While Symantec has agreed to certificate transparency, Blue Coat is a known operator of MITM services they sell to nation-states, and this certificate would allow Blue Coat to issue arbitrary MITM certificates. It's not clear to me why Blue Coat would need to be a trusted CA by all systems and browsers,…

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Security is not obtained by optimistically assuming actors are using their capabilities for good. Sure, there are legit ways they could use this, but the entire point of CAs is that they be trusted actors, and there are very strong reasons not to trust Blue Coat.

Your comment is like discovering the fox has been given the keys to the henhouse and saying "Maybe the fox just wants to hang out with the hens".

Post reply on HN