Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

81–90 of 124 posts

Re: Distrust of Symantec TLS Certificates

#81
post #63

Earlier quoted context omitted.

Because it's wrong. The very post GP linked explicitly says that Symantec certs issued before June 1, 2016 would stop functioning in Chrome 66.

Chrome also blacklisted certs issued after June 1, 2016.

You can imagine how ridiculous this sounds right? If Google had blacklisted these certs in April as you claim, would that have not been a massive shitshow for everyone involved, and would have been on the top of HN?

Re: Distrust of Symantec TLS Certificates

#82
It's been obvious to me for quite a while that EV etc only really tells you "this person paid $$$ to get a cert" rather than anything about the site being trustworthy or being who it says it is. I wouldn't bat an eye if 10 years from now major browsers distrusted everything but letsencrypt. Once the letsencrypt project comes out with a comparable solution for code signing, there is really no more reason for paid cert companies to exist. They don't check shit and it's super easy to get fraudulent certs so the value of what they provide is $0.

Re: Distrust of Symantec TLS Certificates

#83
post #18

PayPal's site is affected by this

That's surprising, because Chrome has distrusted Symantec certs for a few months and it's odd that Paypal would not have fixed it by now.

The head of Symantec's board is the CEO of PayPal.

PayPal is a diehard Symantec company and will not abandon anything Symantec related until it is absolutely forced to.

Re: Distrust of Symantec TLS Certificates

#84

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

Just to be clear : there is no "fix this issue" because the problem is with certs issued _in_the_past_. The only fix is to re-issue the cert and replace the existing one on servers with the new one. This fwiw is easy to do, if you know you need to do it. But then presumably folks running SSL endpoints already knew they had to keep on top of expiry dates, cipher suites and so on so this is just one extra aspect to watch out for. Explicitly tested and reported via ssllabs, of course.

Re: Distrust of Symantec TLS Certificates

#87

Earlier quoted context omitted.

Do you have a source for that? Google's KB articles still reference Chrome 70 [1], and I can't find another reference to this anywhere else. Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set) [1] https://support.google.com/chrome/a/answer/7662561?hl=en

I worked at a large company whose sole supplier was Symantec. Everything has been blacklisted since April.

Yeah. Not true. I visit many sites with Symantec certs in Chrome 69 that don't work in Chrome 70

Re: Distrust of Symantec TLS Certificates

#88
The CA trust model is totally broken! We pay certificate of authority CA companies a lot of money for certificates that are not fully confirmed to be authentic.

Here is a better model. You normally register your company with the local government corporate registration authority. The local government knows who this company is, who the corporate registrars are.

One should use a digital ID card to apply to register a company. The founders sign the registration of the company with their personal digital ID. The company is then registered. To apply for a domain name for a company should be digitally signed. The registration government authority should handle certificate of authentic not foreign CA registrars.

All corporations should use Government CAs all other types of certificates can then be issued by Lets Encrypt having proper DNS validation in place should help there too.

All else is broken security by design.

Re: Distrust of Symantec TLS Certificates

#89
post #64

Earlier quoted context omitted.

Are you sure? Paypal.com's Symantec-issued certificate still works in Chrome, at least on my PC: https://www.paypal.com/

I couldn't be more sure. My company had hundreds of certificates issued from Symantec, who was our main supplier. Basically, all our websites broke the day Chrome was updated. It was hell. If it were actually allowed, I would upload some of the certificates and write a blog post to show you. Paypal has an EV, I don't have EV. Maybe these were not blacklisted. The rest was.

When I visit paypal and open up the console I see the following warning :

The SSL certificate used to load resources from https://www.paypalobjects.com will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information.

Re: Distrust of Symantec TLS Certificates

#90
post #59

Earlier quoted context omitted.

You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?

Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.

https://www.republicservices.com/ is a site with a non-EV Symantec-branded certificate from August 2017 and it still works in Chrome 69 (and is blocked in Chrome 70 with a NET::ERR_CERT_SYMANTEC_LEGACY error).

www.McDonalds.com is another site with a non-EV certificate that will be blocked by Chrome 70, albeit with the GeoTrust brand instead of Symantec directly. Surely McDonalds has a large enough IT division to have noticed and updated by now if Chrome had been blocking their site since April.

Post reply on HN