5 ms·
If it was leaked externally, it'd be more than just pissing off Google, it'd be justification for removing Symantec's CA certs from browsers. I.e., who knows w
by isomorphic 11y ago
If it was leaked externally, it'd be more than just pissing off Google, it'd be justification for removing Symantec's CA certs from browsers. I.e., who knows what other domains Symantec might be "testing" that would go undiscovered because the owners of those domains don't have Google's resources.
But as the other poster says, this probably wasn't leaked at all.
- jMyles 11y ago> it'd be justification for removing Symantec's CA certs from browsers More than half of the CAs have publicly violated trust at some point. The governments of the US and China, who are arguably the biggest threats to HTTPS, still have CAs. While I agree with you wholeheartedly, it doesn't look like either incompetence or malice vis a vis security are substantial enough justifications for the browser makers to pull the plugs here.
- MichaelGG 11y agoCan you point to USG or Chinese CAs that publicly mis-issued or used certs? CNNIC comes to mind and they've been removed. Which others were you thinking about?
- jMyles 11y agoI'm not aware of any; I was just referring to the evident more general contempt for security.
- andreyf 11y agoCNNIC did not mis-use or mis-issue certs, but issued a cert to an Egyptian company which mis-used it, iirc.
- MichaelGG 11y agoUh, issuing a CA cert to the Egyptian company was the very definition of mis-issuing a cert!
- andreyf 11y agoNo, the definition of mis-issuing a cert is when you issue a Google cert to someone who isn't Google. Not doing due diligence on what people to whom you've issued a cert are doing with it is a little different. This is just semantics, though. I think everyone agrees they done bad.