44 ms·
Symantec explores selling web certificates business
- finchisko 9y agoOf course they do. I've feeling they get corrupted and stepped on a path of quick making money with assigning covert certificates for various agencies/companies whose main initiative was to spy on users. In their case recovering trust is almost impossible.
- honestoHeminway 9y agoIf there ever was a fire-sale. Thrustworthiness, get it while its red-hot.
- tialaramex 9y agoHmm. Whilst sale of this business is certainly a possibility, one thing to keep in mind is that the anonymous sources could have been confused by activity that isn't actually a sale at all. Symantec's current deal with Mozilla/ Google implies that they need a third party to actually do most of the technical work while they build new capabilities not tainted by previous problems. So that means Symantec executives having discussions with other CAs that could easily _look_ like they're thinking of selling the business even if they aren't, they'd be talking about sales volumes, sharing financial data, which operational people could be transferred and who needs to stay where they are... all stuff that _looks_ like a sale but would be necessary for Symantec to obey the plan they've shown Google. Also sale of the CA business with the current shadow over it would be problematic, the major trust stores have reacted to the StartCom/ WoSign fiasco by instituting more rules about transfer, which came up for Google recently because they bought a CA. If an existing CA buys the Symantec (Verisign/ Thawte/ GlobalSign branding) business, they also buy Symantec's problems with the trust stores. If a _new_ CA buys the business there will be arguments from a lot of quarters that they're unqualified and forget Symantec's problems the whole thing needs to go away immediately. It's like buying a burning tyre fire, where's the upside ?
- FungalRaincloud 9y agoI'm inclined to agree just from my own reading of this. I just don't see how sale could do anything but harm trust in the brands further, which makes sale only appealing to those who either don't care about trust, or have enough trust on their side to think they can rebuild it. Both of those groups are not going to want to pay much. Why sell a division of your company for peanuts?
- jbergstroem 9y ago> It's like buying a burning tyre fire, where's the upside ? I see it as buying the customer stock with the opportunity of a "fresh start". Rebrand, ensure the that the new organization follows compliance.
- venning 9y agoI'm assuming that Symantec makes money off of selling SSL certs which, again I'm assuming, they will make less of as Let's Encrypt begins to gain "conquest" domains over "greenfield" domains (those that did not and would not have held a cert without ACME and without being free). Of course, that assumes that a substantial number of paid-for SSL users switch to Let's Encrypt. Unless I'm misunderstanding, this may solve two problems for Symantec. EDIT: I have no idea if LE's impact is of a "rising tide raises all boats" kind or a purely disruptive kind.
- gcp 9y agoThe DV business is dead but there will be a marketing push towards EV certs for business. Symantec's problems are that they fucked up too much and have slipped past the "too big to fail" boundary.
- mrweasel 9y agoThere's also a niche market for more complex certificate solutions, like the one we saw stackoverflow required: https://nickcraver.com/blog/2013/04/23/stackoverflow-com-the-road-to-ssl/ https://nickcraver.com/blog/2013/04/23/stackoverflow-com-the... It's just that those solutions require actual work and capable customer support, and I don't think that's a business Symantec wants to be in. Still I would hope that their certificate business is taken over by someone serious about SSL/TLS/certificates. I would have for Let's Encrypt to become a monopoly.
- wfunction 9y agoTheir biggest problems seemed to just stem from their arbitrary choice to use subdomains instead of subdirectories. If they just put everything on the same domain (/sites/stackoverflow, /sites/superuser, etc.) then they would literally just need 1 certificate for everything, no third-level-wildcard nonsense. Not sure what this decision to have a gazillion different domains has gained them honestly. Reddit clearly manages to work that way.
- mrmondo 9y agoBeing one of the least trusted, yet large CAs currently in existence this may not be a bad move for the company. However I do wonder what that leaves the company as far as popular assets go, their ‘enterprise’ antivirus offering was once the best-in-class but since the demise of AV and the companies general reputation declining year on year (citation definitely needed and obviously my opinion through observation) it still makes me wonder how long the company will last. Oh and of course I should remind people that Symantec owns Blue Coat...
- eru 9y agoOf course, even with nothing useful left in the rump company, the sale might still be good from a shareholders point of view. Similar logic as for Yahoo's holding of Alibaba a while ago, when rump-Yahoo added negative value by most calculations.
- mrmondo 9y agoVery good point, in your eyes does that suggest inevitable liquidation / similar or something more like running the company at a loss as a write off and on the chance something might come from it as a spin off?
- eru 9y agoThanks to limited liability, it is very hard for companies to ever run the risk of negative value. Equity can be seen as a call option on liquidation value (plus dividends). So both options might be viable for rump Symantec: sale of assets / liquidation, or keep running it and hope for the best. That's from a economics point of view. From a more cynical point of view: shareholder capitalism is mostly a lie. Principal agent problems are real, and most companies are run for the benefit of management. And since managers are more important and can justify higher pay with an empire below them, the divestment will rarely happen. Especially if like for Yahoo (and perhaps Symantec) it would reveal in stark and undeniable terms that that very management of the parent company actually _subtracts_ value. Some people did ingenious studies in this area: they checked how share prices reacted to unanticipated CEO deaths, like accidents. If management really served at the whim of shareholders, you'd expect that they'd have the best person they can afford. In practice, the share price goes up on CEO death as often as down. That means shareholders are often happier with the average expected next candidate for CEO than the one they currently have---but since they can't get rid of the incumbent that preference is only revealed on accidents. (I couldn't find the studies quickly, but I found a quora discussion that might lead you there https://www.quora.com/Why-do-companies-stock-prices-rise-after-their-CEO-leaves-the-company https://www.quora.com/Why-do-companies-stock-prices-rise-aft...)
- aburan28 9y agoFun Fact: Symantec sold certificates to Blue Coat all the way back in May 2016 and have been using them in their SSL inspection tool ever since
- phonon 9y agoSymantec owns Blue Coat though?
- deleted 9y ago[deleted]