9 ms·
Symantec Distrust in Firefox Nightly 63
- ehPReth 8y agoA (incomplete) list of broken sites: https://bugzilla.mozilla.org/show_bug.cgi?id=1484006 https://bugzilla.mozilla.org/show_bug.cgi?id=1484006
- sp332 8y agoAlso accounts.intuit.com which affects various products e.g. Mint. And an interesting comment from the thread: Enforcement of this error can be disabled by setting security.pki.distrust_ca_policy to '1' in about:config. Changing the value back to '2' will re-enable this change.
- snowwolf 8y agoAdd PayPal. And theirs is an EV cert "valid" till 2019. Bet they're happy having to go through the process all over again.
- sofaofthedamned 8y agoConsidering the PCWorld group in the UK have had to disclose a serious breach recently, plus they have not bothered to update their EV certs, i'd suggest their security isn't up to scratch and black hats will notice this.
- chuckgreenman 8y agoIf you're wondering why Symantec certificates are being distrusted Mozilla enumerates a pretty good list of reasons here: https://wiki.mozilla.org/CA:Symantec_Issues https://wiki.mozilla.org/CA:Symantec_Issues
- unethical_ban 8y agoSo is this costing Symantec a lot of money? Are they no longer a root CA in any capacity?
- detaro 8y agoThey sold their CA business to DigiCert and quit the market.
- exsymcemployee 8y agoProbably for the best. They really buggered up the whole CA thing. Hard to establish trust after it's been violated.
- lxe 8y agoIt's been distrusted in Chrome Canary for a few weeks already. Similar schedule and post: https://security.googleblog.com/2018/03/distrust-of-symantec-pki-immediate.html https://security.googleblog.com/2018/03/distrust-of-symantec... Sites like PayPal and Intuit, which should be on top of things related to security, have been non-responsive to my pings to fix it.
- dc_gregory 8y agoIirc, PayPal responded to a previous support request from us stating they were aware.
- pietroglyph 8y agoIt's interesting that Firefox preserves the "Continue" button for affected sites, while Chrome does not. I get that we want to keep broken sites relatively accessible for a while, but I worry that we could also be teaching people to ignore warnings like these. I wonder if the continue button dissapears with HSTS…
- antsar 8y agoIt does. I’ve found the inconsistency somewhat odd.
- morganvachon 8y agoWell, to get to the continue button you have to click once, then after you click continue you have a new dialog asking if you're sure you want to trust the certificate and whether you want to trust just for the session or permanently. It's not idiot-proof, but then nothing in software ever is.
- cat199 8y agosounds like you've never needed to diagnose a broken cert before.. all of this nannying for the common good and breaking functionality is not always a good thing. provide sensible defaults and give the user control to override it as they see fit (like the continue button)
- joombaga 8y agoI agree with you, but the continue button does seem too easy. I'd make this an about:config type setting.
- abdullahkhalids 8y agoProbably because Mozilla subscribes to the ethos that a user should get the final say in what computation gets done on their computer, and not some third party. I would be sad if they ever took the "continue" option away. This is consistent with their position on drm in browsers.
- 8y ago
- floatboth 8y agoOh, I guess that's why I've been seeing TLS errors on eBay description pages…