5 ms·
Wow, talk about an obscure warning that tells nothing to the domain owner.
by frandroid 8y ago
Wow, talk about an obscure warning that tells nothing to the domain owner.
- olliej 8y agoSymantec should have contacted everyone they issued a certificate to.
- LinuxBender 8y agoWhile that is true, all service providers, VPS providers, cert resellers, hosting companies have known about this for over a year and should have replaced all of these certs by now as well as contacting cert holders.
- pvg 8y agoThey're still exceptionally user-hostile warnings. You can get this running a pre-release browser (and I doubt that they'll be changed for the stable releases of either FF or Chrome) trying to visit Paypal. It's utterly bananas to present this to an end-user doing a very common, security-dependent interaction.
- jleedev 8y agoNobody who runs a website can pretend to be ignorant of this fiasco.
- Spivak 8y agoI mean with the huge number of set-and-forget Wordpress installations I could absolutely believe people are ignorant of this. I mean why would anyone outside of professional webdevs even care? It's not like this news escaped the tech bubble.
- fpoling 8y agoThose forgotten Wordpress installs may not even have https support.
- josho 8y agoI knew that my sites weren't at risk because I don't have Symantec certs. It was only triple checking things today that I discovered RapidSSL is a Symantec cert and I am in fact affected.
- notatoad 8y agoI don't have a copy of Firefox handy to check, but IIRC the message in the inspector is a bit more descriptive. The message screenshotted in the article is a message to the website visitor, not to the domain owner. And not going out of their way to shame Symantec to every visitor to a site with a Symantec cert is probably a decent policy. Even without their cert business, Symantec is a big player that the browser vendors will have to work with in the future.