6 ms·
He's arguing that the various issues that lead to Symantec being gradually distrusted mean that they believed all their existing non-expired, non-revoked certif
by pfg 9y ago
He's arguing that the various issues that lead to Symantec being gradually distrusted mean that they believed all their existing non-expired, non-revoked certificate were compromised (in the sense that they should not be trusted) and should be revoked.
Maybe it's just me, but a company who stores their customer's private keys, sends them around in a ZIP file via email and has a trivial code injection vulnerability on their site, with a process running as root, is probably not the one I want to make that call.
- BuildTheRobots 9y ago> Maybe it's just me, but a company who stores their customer's private keys, sends them around in a ZIP file via email and has a trivial code injection vulnerability on their site, with a process running as root, is probably not the one I want to make that call. On the flip side, if a company with such little regard for security thinks there's a problem with the Symantec, you've got to wonder. They're basically saying "we're dangerously incompetent, however even _we_ can see that Symantec are broken" - and might actually have a point.
- pfg 9y agoSymantec is already getting distrusted and the Web PKI community has decided on a plan that minimizes user impact while doing that. It's very doubtful that a company as incompetent as Trustico has the expertise to come up with a more well-informed decision or a better approach. Certainly attempting to get 50,000 certificates revoked immediately without doing any work to reissue those certificates prior to that is a terrible approach. Considering the fact that they recently switched to a new CA partner, a more likely explanation is that this was a misguided attempt to somehow keep their existing business rather than let DigiCert pick them up somehow. Obviously it failed in a spectacular fashion.
- amluto 9y agoBut this is all nonsense. Symantec never had the private keys, so there was nothing at all unsafe about the certificates.
- dragonwriter 9y ago> Maybe it's just me, but a company who stores their customer's private keys, sends them around in a ZIP file via email and has a trivial code injection vulnerability on their site, with a process running as root, is probably not the one I want to make that call. I dunno. If a company knows that it does all those things, I think that it is 100% correct in making the call that all of its active certificates should be treated as compromised.
- pfg 9y agoThey're not claiming the certificates were compromised because of their own practices, in fact they repeatedly emphasise that there was no issue on their end. I'm not questioning that the certificates became compromised the moment they sent them via email, or really the moment they generated and stored them given the level of security competence they've shown thus far.
- dragonwriter 9y ago> They're not claiming the certificates were compromised because of their own practices I didn't say their reasoning was correct, only the conclusion.