Earlier quoted context omitted.
That's actually a possibility but I very much doubt this would be used in practice. Apart from the scaling problem there is a more serious problem which would make use of this certificate for lots of MITM impossible: - today's browsers use certificate pinning, i.e. Chrome, Firefox... have predefined lists of sites where they know which public key to expect. One example of such a site is google.com. - The browser will…
> today's browsers use certificate pinning, i.e. Chrome, Firefox... have predefined lists of sites where they know which public key to expect. One example of such a site is google.com. Yes, this may be true, but the list is quite small. You may not be able to trick Chrome into connecting to a fake google.com certificate but there's lots other "high security site[s]" as Adam Langley suggests[1] should apply when they…
Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
91–100 of 118 posts
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#92'azet noted in another forum that with pathlen:0, this cert cannot be used to issue other intermediate certs, such as they would to place in a traffic inspection device.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#93'azet noted in another forum that with pathlen:0, this cert cannot be used to issue other intermediate certs, such as they would to place in a traffic inspection device.
Blue Coat can trivially work around this limitation by placing the intermediate cert on a server. Now when the traffic inspection device wants a (leaf) cert, it calls home to the server and the server provides it.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#94I wonder just how many certs I'd notice failing if I pulled Symantec's root out of my keystore - and if I'd get any mileage contacting the sites that end up broken and explaining why. This is exactly the sort of thing I'd like to have the "CA death penalty" seriously considered against Symantec - but I fear they're going to be judged "too big to fail". A grass roots campaign of contacting sites (especially sites I've…
What I would really like to see is a curated list of CAs and intermediates instead of the huge list my browser currently trusts. Preferably a browser extension like EFF's Privacy Badger, to make it easier to use. I have gone into Firefox's settings and deleted random certs like the Hong Kong Post Office and this didn't break any of the sites I use, but all certificates are re-installed each time Firefox updates. Thin…
Even a (mainland) Chinese user won't be able to distrust American CA's and still browse the Internet fine, and it is known that China's network is one of the most isolated one on earth filtered by the GFW. For example, Baidu's certificate is signed by Verisign, Taobao by GlobalSign, QQ by GeoTrust. All of those certificate authorities all headquartered in the United States.
CA's like Symantec is just too big to fail, even if your proposal is implemented.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#95This sounds like a good time to mention https://perspectives-project.org/ . It augments the standard CA trust model with one based on figuring out what certs everyone else is seeing, and whether or not that's changed recently. I think it's been a little bit inactive of late, due to poor takeup - but it would certainly benefit from more users and more people contributing to the project.
I just checked out the website, and found it interesting. And then I found it only has a Firefox extension, but not a Chrome extension. Given that the Chrome's market share is several times that of Firefox globally, maybe that is the reason of the poor takeup?
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#96Earlier quoted context omitted.
Even Cloudflare doesn't use their own CA, but they have a relationship with Comodo; at least, from what I can tell on services I use with Cloudflare. If they just need to issue lots of certificates, or make it easy for client devices to get certificates, or even for their own cloud services, they could use LetsEncrypt. There are very few use cases where having your own CA is necessary, and for a company like Blue Coa…
We have relationships with Comodo, DigiCert, and GlobalSign. A large part of our Universal SSL issuance is currently through Comodo, which is probably what you noticed. (We've considered acquiring our own CA or subCA in the past but the audit requirements are quite onerous, at least after the first year, and sometimes it's nice to have someone handle certain aspects for you.) The most important thing to pay attention…
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#97I'd forgotten that Symantec had acquired Verisign at some point and they are huge certificate supplier. I was planning to untrust Symantec but not sure that is feasible for the Verisign certs too.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#98'azet noted in another forum that with pathlen:0, this cert cannot be used to issue other intermediate certs, such as they would to place in a traffic inspection device.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#99Earlier quoted context omitted.
~30%
How did we allow a single company to own 30% of a market, despite its expensive pricing ( https://www.symantec.com/en/uk/theme.jsp?themeid=compare-ssl... )? Comodo and Synantec are 32% each, then goes others. StartSSl is significant but 2%, Let'sEncrypt tiny for now: https://w3techs.com/technologies/history_overview/ssl_certif...
Let's Encrypt's root is not trusted by any browser yet, so they got a cross-signature from IdenTrust. So far, basically everybody using Let's Encrypt chains to the IdenTrust root.
Given that IdenTrust grew from "https://letsencrypt.org/stats/ , I strongly suspect that the 5.6% market share credited to IdenTrust actually belongs to Let's Encrypt.
As a check, we can divide 2/3 of the total unexpired Let's Encrypt certificates (~2.8M as of last week, 2/3 because standard practise is to renew a 90 day cert after 60 days, so 1/3 are probably overlapping = 1.86M) by the total number of https sites (I had a hard time finding this, but http://arstechnica.com/security/2016/03/more-than-13-million... claims that 5.9M is 17% of https servers, so 34.7M), and we get 5.4%, which is almost the same number as the IdenTrust number above.
That's still nowhere near Comodo, but it's not completely insignificant.
Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services
#100Earlier quoted context omitted.
If you have a problem with that, use your own network.
Do you see no value in SSL at all, then?
If you provide a publicly accessible "Guest" network isolated from my corporate or private resources, that I agree that it's unreasonable to intercept TLS sessions.
If you are on my network, which exists to serve my constituents with a personal device, I have every right to or even have a duty to ensure that you aren't threatening the overall integrity of the private network. Whether that be exfiltrating data, bringing in malware, etc.
In 2016, the answer to this issue is really simple -- bring your own cellular service.