Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

81–90 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#81
post #43

You know, the main job for a web CA is to verify the owner of a domain. What if... domain registrars had that job instead? They definitively know the domain registrant, no need to play games with email verification tokens or http challenges.

and then hope that every registrar out there is honest...

Not really, it could be set up so registrar CAs would only be valid for domains they are registrars for. Then you just need to pick one trustworthy registrar for your own domains, and you're set. If you can't trust your registrar with your domains, you have bigger problems anyway.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#82
post #15

Earlier quoted context omitted.

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…

May Symantec's authority can be revoked completely, if proof of misuse is found?

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#83
post #9

So, how much of my internet will break if I distrust the Symantec cert on my machine?

~30%

How did we allow a single company to own 30% of a market, despite its expensive pricing (https://www.symantec.com/en/uk/theme.jsp?themeid=compare-ssl...)?

Comodo and Synantec are 32% each, then goes others. StartSSl is significant but 2%, Let'sEncrypt tiny for now: https://w3techs.com/technologies/history_overview/ssl_certif...

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#84
post #82

Earlier quoted context omitted.

It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…

May Symantec's authority can be revoked completely, if proof of misuse is found?

Assuming that Symantec doesn't manage to deflect onto Bluecoat, and assuming that browser vendors are willing to actually revoke one of the largest CAs for misuse rather than wagging their finger.

The last time Symantec made a "mistake" with their CA (https://security.googleblog.com/2015/10/sustaining-digital-c...), Google said "Therefore we are firstly going to require that as of June 1st, 2016, all certificates issued by Symantec itself will be required to support Certificate Transparency." Interesting wording, "by Symantec itself". And now, a few days before June 1st, Symantec issues an intermediate CA certificate to a known vendor of MITM systems, so that Bluecoat can issue certificates themselves rather than having their "certificates issued by Symantec itself".

I wonder if Bluecoat will support Certificate Transparency?

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#85
post #15

Earlier quoted context omitted.

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…

It may be acceptable in certain states and jurisdictions, but it is throughly illegal in others. Remember you aren't just MITMing your own network, if someone from your network connects to my server you are MITMing me too and you have not obtained my consent for that. Even if your state is a one party consent state, mine may not be or have laws that heavily restrict interception.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#86
post #45

Earlier quoted context omitted.

I'm good with my work or school owned/issued device trusting a root cert installed by that device's owner. I'm _not good with a school or employer's network being able to generate arbitrary certs for my email, bank, social networks, etc - WITHOUT ME KNOWING ABOUT IT ON MY PERSONAL DEVICES... Sure, MitM me if it's your network - but I 100% should be able to rely on my browser on my device reliably being able to tell m…

If you have a problem with that, use your own network.

What if the site they're connecting to has a problem with that? If I for example serve E-Healthcare records, and have an agreement that a given person that I have vetted has access to them, I might have a problem with your unvetted IT staff having access but how would I know?

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#88
This sounds like a good time to mention https://perspectives-project.org/. It augments the standard CA trust model with one based on figuring out what certs everyone else is seeing, and whether or not that's changed recently.

I think it's been a little bit inactive of late, due to poor takeup - but it would certainly benefit from more users and more people contributing to the project.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#90

Earlier quoted context omitted.

It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…

It may be acceptable in certain states and jurisdictions, but it is throughly illegal in others. Remember you aren't just MITMing your own network, if someone from your network connects to my server you are MITMing me too and you have not obtained my consent for that. Even if your state is a one party consent state, mine may not be or have laws that heavily restrict interception.

He isn't talking about the legality of it at all. He is talking about what the browsers include in their trust store.
Post reply on HN