5 ms·
> Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates When I read that something like this popped up in my head: "Google is using t
by musicnarcoman 10y ago
> Intent to Deprecate and Remove: Trust in Existing Symantec-Issued Certificates
When I read that something like this popped up in my head:
"Google is using the nuclear option on Symantec. Neat!"
- Shanea93 10y agoPerhaps it's neat for you, I just found out that our newly issued EV certificate status is being revoked in the next build of Chrome, so our expensive EV certificates may as well be $5 StartSSL certificates. I imagine that there will be a lot of angry customers asking for refunds from Symantec/Verisign for certificates already issued which no longer conform to the offered product.
- ChristianBundy 10y agoHow recently did you renew? This has been in the works for over two years,I'm surprised that anyone is still giving them business.
- hannob 10y agoI for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.
- Shanea93 10y agoAbsolutely, I totally get that, it's worth mentioning that we take our TLS implementation seriously (HSTS, no TLS1.0, etc) and score an A+ on SSLLabs test: http://i.imgur.com/QbH4YZS.png http://i.imgur.com/QbH4YZS.png The green bar with our company name in it translated in to a measurable conversion increase week for week from guest checkouts, so saying it's a waste of money isn't strictly true in our case.
- dan1234 10y agoIt proves (if the issuer has done their job) that the organisation requesting the certificate has been properly vetted, so you’re more likely to be doing business with the right website.
- zorpner 10y agoAs the neighbor comment points out, EV validation is absolutely not a waste of money. I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. They don't improve security -- that is true.
- ceejayoz 10y ago> I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. That's a bit hard to reconcile with the fact that Amazon.com can't be bothered to get one.
- the8472 10y agoamazon has brand recognition, they don't need to assuage people's semi-conscious perception of site trustworthyness.
- rcthompson 10y agoMost outliers are hard to reconcile with the mean.
- msbarnett 10y ago
- deleted 10y ago[deleted]
- beedogs 10y agoShould've gone with a better vendor. Symantec has been a known bad actor in this field for years now.
- the8472 10y agoIf they're going nuclear then it's akin to merely lobbing tactical nukes on military bases, not city-busters on some megalopolis. They're "only" planning to remove the extended validation indicator and reduce the maximum validity time instead of completely phasing out the root.