Live data from Hacker News

Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

sslmate.com

91–95 of 95 posts

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#91
post #89
post #24

Earlier quoted context omitted.

Is there any reason, in 2016, to use Symantec over LetsEncrypt?

Apart from the reasons posted earlier, "legacy" also comes into play. Symantec acquired the CA business from the old VeriSign in 2010, which back then was the largest CA and had a large corporate client portfolio accustomed to paying $$$$ per certificate per year. Corporations can become very reluctant to change, even if it benefits them, and there are some who just pay up every year without researching alternatives…

And they tends to need legacy stuff such as SHA-1 certificates more often.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#92

Earlier quoted context omitted.

That means it uniquely identified you to Google every day then, right?

Does it? Does the request actually provide enough to uniquely identify you?

Source code: https://chromium.googlesource.com/chromium/src/+/master/comp...

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#93
post #79

Earlier quoted context omitted.

» When Chrome starts up, it fetches a list of feature flags from a Chrome server using a system called Finch which is independent of the normal upgrade system. I'm not a Chrome user. But that sounds awful at first. What is the idea behind this service? Is there any documentation about the 'features' these flags can enable/disable? I understand that I'm paranoid at times AND I really dislike Google, but why would you…

because Google don't know bugs on your (their) browser affecting their revenue. interesting, if you're a victim of mitm attacks, i wonder if attackers can abuse that to disable some certificate check features to make spoofing ssl sites easier.

I think they use TLS and they use cert pinning for Google domains.

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#94
post #81

Earlier quoted context omitted.

That means it uniquely identified you to Google every day then, right?

> using a Google browser > not wanting to be tracked here's a hint: ad impression for unknown user is 0.01$ and for logged in user 2$. guess why Google has a browser now...

Do you mean logged into Chrome (e.g. profile sync)? or just logged into Gmail?

Re: Why Chrome 53 Is Rejecting Chase Bank's Symantec Certificate

#95
post #81

Earlier quoted context omitted.

> using a Google browser > not wanting to be tracked here's a hint: ad impression for unknown user is 0.01$ and for logged in user 2$. guess why Google has a browser now...

Do you mean logged into Chrome (e.g. profile sync)? or just logged into Gmail?

does not matter at all.

if you have a logged-off cookie, and the publisher can associate you with a logged-in user at a near point in time, they can charge you as logged in impression.

Post reply on HN