Live data from Hacker News

Distrust of Symantec TLS Certificates

blog.mozilla.org

91–100 of 124 posts

Re: Distrust of Symantec TLS Certificates

#91
post #59

Earlier quoted context omitted.

You mean this roadmap? https://security.googleblog.com/2017/09/chromes-plan-to-dist... That plan clearly states that all Symantec-issued certificates with a not-before date before June 1, 2016 would be distrusted in April. Is that not what happened?

Yes, this roadmap. It was not followed. All certificates were blacklisted in April, irrelevant of their date.

Uh, we used to use them, and switched in June. Our certificates behaved normally. I have no idea what was going on with yours, but clearly "all certificates" were not.

We also received I don't know how many notifications of the impending changes. They were plentiful enough that it got annoying. Assuming one actually has valid email addresses to which attention is paid for these communications.

Re: Distrust of Symantec TLS Certificates

#92

It's just insane that they haven't been able fix this issue and get back into good standing with 6 months warning.

The base issue is trust, not some technical issue.

They repeatedly violated the trust placed in them. They'd have to fire the entire chain of command that allowed those to happen, retool their processes, and probably post a sizable bond before many folks would give them a second chance.

But really, who needs them? We need fewer registries, or in the alternative many, many, many more.

Re: Distrust of Symantec TLS Certificates

#93
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

Also, there is a warning in Chrome dev tools console.

Re: Distrust of Symantec TLS Certificates

#94

Earlier quoted context omitted.

Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this: Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate. Six months later Bob leaves to work at some other c…

Exactly. Just about every organization I've worked for has gone through a consolidation phase where DNS registration and certificate issuance is consolidated and formalized. You don't have to get very big before these issues surface and cause tons of problems and toil.

Didn't Hotmail have some problem where microsoft took over and forgot to pay for the domain name [0]?

[0] https://whoapi.com/blog/5-all-time-domain-expirations-in-int...

Re: Distrust of Symantec TLS Certificates

#95
post #69

Earlier quoted context omitted.

Well, a specific example that's going to bite _plenty_ of medium to large sized corporations is that you have a pattern like this: Big Corp's Division Z need a cert for their new web site https://www.division-z.example/ and so Bob buys it with his corporate credit card, and gives as contact details bob@bigcorp.example. He buys, let's say, a Verisign SSL certificate. Six months later Bob leaves to work at some other c…

Oh I know that it's widespread, it happened here; the guy who's job it was to care left and didn't pass on knowledge when he did. It is because there was a a role account assigned to comms about TLS certs that the notices were, well, noticed. I've worked in large orgs where comms are even worse. But my point was that this is not some reckless sudden move by the browsers or DigiCert. In my observation, they have been…

Question: with such big news going on for such a long time, how does not even one person -- whether manager or otherwise -- just take 5 seconds to ask if they are prepared for it? It's not like the reporting on this was just in some dark corners of the internet... /some/ people in a given company should have at least heard something was going to happen to Symantec certificates.

Re: Distrust of Symantec TLS Certificates

#96
post #69

Earlier quoted context omitted.

Oh I know that it's widespread, it happened here; the guy who's job it was to care left and didn't pass on knowledge when he did. It is because there was a a role account assigned to comms about TLS certs that the notices were, well, noticed. I've worked in large orgs where comms are even worse. But my point was that this is not some reckless sudden move by the browsers or DigiCert. In my observation, they have been…

Question: with such big news going on for such a long time, how does not even one person -- whether manager or otherwise -- just take 5 seconds to ask if they are prepared for it? It's not like the reporting on this was just in some dark corners of the internet... /some/ people in a given company should have at least heard something was going to happen to Symantec certificates.

Because there are tickets to close before the whistle.

Re: Distrust of Symantec TLS Certificates

#97
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

I've received those emails as well. The emails came from our domain registrar. We don't buy certificates from our domain registrar. Adding to the confusion the email refers to Symantec certificates of which we don't have any, I even double checked the certificate chain and Symantec wasn't involved.

So, for the longest time I assumed the emails were a phishing scam and disregarded them. Only today when I tried testing with Firefox did I realize that several certificate brands were handled by Symantec and that YES I was affected.

So, yes there has been plenty of forewarning, but yet was surprised today.

Re: Distrust of Symantec TLS Certificates

#98
post #65
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

I was a technical lead for a project involving a) governments and b) lots of income from taxpayers, and I noticed this warning about Symantec certs a while ago from a Qualys scan I ran on the third-party payment website. I told my manager and our client about this several times before being laid off, and I would bet they never did anything about it. I'm wondering how this is affecting them.

When it actually /breaks/ something they'll divert resources to fixing it.

Re: Distrust of Symantec TLS Certificates

#99
post #97
post #47

There's been downvoted comments below that, to me, seem to complain of Mozilla unfairly blindsiding domain owners. I disagree, based on my own personal experience. This has been coming for a while, with plenty of forewarning. My employer uses certificates from one of Symantec's brands. Last year, we began to get notices that Chrome et. al. would be distrusting the certificates issued from the old Symantec root this y…

I've received those emails as well. The emails came from our domain registrar. We don't buy certificates from our domain registrar. Adding to the confusion the email refers to Symantec certificates of which we don't have any, I even double checked the certificate chain and Symantec wasn't involved. So, for the longest time I assumed the emails were a phishing scam and disregarded them. Only today when I tried testing…

I'm curious if you received the same emails I did. We got ours from our cert vendor, so I suppose that's as about as direct as it can get. If your domain registar was crafting their own, then I could see how you might have gotten blindsided. There's always a risk of information loss when the game of telephone comes into play.

When I first started looking at this myself, I was surprised at just how many TLS cert brands Symantec held: damn near half of them.

Re: Distrust of Symantec TLS Certificates

#100
post #82

It's been obvious to me for quite a while that EV etc only really tells you "this person paid $$$ to get a cert" rather than anything about the site being trustworthy or being who it says it is. I wouldn't bat an eye if 10 years from now major browsers distrusted everything but letsencrypt. Once the letsencrypt project comes out with a comparable solution for code signing, there is really no more reason for paid cert…

I would bat an eye because it's never good to rely on a single point of failure.

Imagine, for instance, that at some point, LE is the only trusted CA for code-signing. If its root key gets compromised for some reason, how are we supposed to move to a new CA if the auto-updaters cannot trust the old CA anymore?

Post reply on HN