TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sustaining Digital Certificate Security

260 pointsby fred256over 9 years ago

12 comments

nailerover 9 years ago
&gt; It’s obviously concerning that a CA would have such a long-running issue and that they would be unable to assess its scope after being alerted to it and conducting an audit. Therefore we are firstly going to require that as of June 1st, 2016, all certificates issued by Symantec itself will be required to support Certificate Transparency.<p>Symantec said they did an audit, Google spent &#x27;a few minutes&#x27; and found many more mississued certificates just from the CT logs. In other words, Symantec can&#x27;t audit themselves, so Google now require public issuance logs for all their certificates.<p>&gt; [Google] expect Symantec to undergo a Point-in-time Readiness Assessment and a third-party security audit.<p>This is a massive (and justifiable) smack in the face to Symantec.<p>Disclaimer: we&#x27;re a Symantec competitor, as you may have realised:<p><a href="https:&#x2F;&#x2F;certsimple.com&#x2F;blog&#x2F;seal-in-search" rel="nofollow">https:&#x2F;&#x2F;certsimple.com&#x2F;blog&#x2F;seal-in-search</a><p><a href="https:&#x2F;&#x2F;certsimple.com&#x2F;blog&#x2F;sgc-ssl-certificates" rel="nofollow">https:&#x2F;&#x2F;certsimple.com&#x2F;blog&#x2F;sgc-ssl-certificates</a>
评论 #10467662 未加载
评论 #10468318 未加载
tshtfover 9 years ago
Days after the initial reports of rogue certificates being issued, Symantec wrote in their blog that they had already fired employees:<p><i>In addition, we discovered that a few outstanding employees, who had successfully undergone our stringent on-boarding and security trainings, failed to follow our policies. Despite their best intentions, this failure to follow policies has led to their termination after a thoughtful review process... At the end of day, we hang our hats on trust, and that trust is built by doing what we say we’re going to do.</i><p><a href="http:&#x2F;&#x2F;www.symantec.com&#x2F;connect&#x2F;blogs&#x2F;tough-day-leaders" rel="nofollow">http:&#x2F;&#x2F;www.symantec.com&#x2F;connect&#x2F;blogs&#x2F;tough-day-leaders</a><p>It&#x27;s starting to look now like this the fault of systemic flaws at Symantec, and not just a few employees who didn&#x27;t follow procedure.
评论 #10467951 未加载
evmarover 9 years ago
It makes me* uncomfortable that Google has effectively appointed themselves as the internet police and using their power to push people around like this. But at the same time, there is nobody else (?) who is taking care of this, and I suppose the good of someone&#x2F;<i>anyone</i> looking into and taking action on the sorts of serious problems that Symantec has exhibited probably outweighs my discomfort.<p>* Disclaimer: Google employee, no connection to any of this cert stuff.
评论 #10467776 未加载
评论 #10467744 未加载
评论 #10468770 未加载
评论 #10467766 未加载
评论 #10468083 未加载
评论 #10468713 未加载
评论 #10468061 未加载
评论 #10467838 未加载
评论 #10468062 未加载
pilifover 9 years ago
A clear example of too big to fail. If this was any smaller CA (like cnnic before), they would now be gone from the trusted roots.<p>I wonder what&#x27;s coming out of this. Personally, I think Symantec doesn&#x27;t care in the least about Google&#x27;s sabre rattling here. It&#x27;s clear to everybody that Google hardly wants to release a browser which doesn&#x27;t display 50% of the encrypted web sites.<p>This is a further issue with the current PKI: too few CAs are around (after symantecs buying spree lately) which gives them way too much power to do what ever they want. Furthermore, the process of acquiring a certificate (especially an EV one) makes switching CAs very burdensome, so not even bad reputation will compel people to leave.<p>What a mess.
评论 #10469748 未加载
gefhover 9 years ago
Is the CA model just unfixably broken at this point? What should replace it if so?
评论 #10468106 未加载
评论 #10467996 未加载
评论 #10468371 未加载
评论 #10468626 未加载
评论 #10468166 未加载
bracewelover 9 years ago
&gt;Symantec performed another audit and, on October 12th, announced that they had found<p>&gt;an additional 164 certificates over 76 domains and 2,458 certificates issued for<p>&gt;domains that were never registered.<p>:|
SimeVidasover 9 years ago
I don’t know much about how the CA system works, but “there’s something fishy going on with this CA” in conjunction with “starting with June 1st 2016” is not very reassuring.
评论 #10468414 未加载
评论 #10468417 未加载
bpolveriniover 9 years ago
All the more reason why client-side encryption needs to become part of our daily interaction with software and cloud services.
评论 #10467696 未加载
chetanahujaover 9 years ago
To state the obvious (again) the third-party based trust system underlying TLS is broken. It places a massive amount of faith in a large crowd of human beings (the collective employee populations of all the CA&#x27;s in the world) to behave with absolute rectitude and discipline for years and years without fail.<p>The sad part is that all of us, collectively, trust pretty much our entire financial lives and other matters requiring secrecy and authentication to this system everyday. It&#x27;s mind-boggling how we came to be in this situation. How did the entire society, including very very smart security experts came to vouch for and blindly trust this system?
systemzover 9 years ago
DNS certs would be better <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;DNS-based_Authentication_of_Named_Entities" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;DNS-based_Authentication_of_Na...</a>
yuhongover 9 years ago
This reminds me of <a href="https:&#x2F;&#x2F;www.agwa.name&#x2F;blog&#x2F;post&#x2F;how_to_responsibly_misissue_a_cert" rel="nofollow">https:&#x2F;&#x2F;www.agwa.name&#x2F;blog&#x2F;post&#x2F;how_to_responsibly_misissue_...</a>
late2partover 9 years ago
This is terrible. This is sad. Is it any wonder so many people have no faith in Government, in the Financial system? How much of the system we take for granted is corrupt? I&#x27;m not intending to be negative, I know I am. But for Pete&#x27;s sake. This sucks sucks sucks.