4 ms·
> The point of the first part of their post is not "we're too big", it's "a move like this would disrupt the lives of an awful lot of people." The real questio
by Aaron1011 9y ago
> The point of the first part of their post is not "we're too big", it's "a move like this would disrupt the lives of an awful lot of people."
The real question is, what effect would doing nothing have on all of those people? If Symantec continues to mis-issue certificates (as they have done repeatedly: https://wiki.mozilla.org/CA:Symantec_Issues https://wiki.mozilla.org/CA:Symantec_Issues), keeping their EV status intact could be much, much worse for them.
> As the blog post states explicitly, there are a lot of use cases where updating a deployed app is very difficult, almost impossible, or cost prohibitive.
As others have pointed out, this change would actually have no effect on the 'complex dependencies' Symantec identified:
* This has absolutely no effect on embedded devices, which are certainly not running Chrome.
* Mobile applications that pin certificates shouldn't be affected, since the very fact that they're pinning certificates means they're not using Chrome (there's no way for an app to tell Chrome to pin a specific certificate).