4 ms·
> This action was unexpected, and we believe the blog post was irresponsible. Problems since Oct 2015 and the action unexpected? see 1) > We hope it was not c
by c3t0 9y ago
> This action was unexpected, and we believe the blog post was irresponsible.
Problems since Oct 2015 and the action unexpected? see 1)
> We hope it was not calculated to create uncertainty and doubt within the Internet community about our SSL/TLS certificates.
Symantec took no ownership of the issue. Snarky underhanded remarks are not a professional way to address shortcomings in managing their product.
> For example, Google’s claim that we have mis-issued 30,000 SSL/TLS certificates is not true. In the event Google is referring to, 127 certificates – not 30,000 – were identified as mis-issued, and they resulted in no consumer harm.
Per Chrome's team an initial set of reportedly 127 certificates has expanded to include at least 30,000 certificates, issued over a period spanning several years see 2)
Summary: No ownership and no action plan conveyed in Symantec's 421 word message.
1) https://security.googleblog.com/2015/10/sustaining-digital-certificate-security.html https://security.googleblog.com/2015/10/sustaining-digital-c...
2) https://groups.google.com/a/chromium.org/forum/#!msg/blink-dev/eUAKwjihhBs/rpxMXjZHCQAJ https://groups.google.com/a/chromium.org/forum/#!msg/blink-d...
- tyingq 9y agoFrom your 1) link... "23 test certificates had been issued without the domain owner’s knowledge covering five organizations, including Google" Guess that explains part of why this particular CA incident has Google's full attention.
- hackcasual 9y agoI believe the 30,000 is from how many certificates 3rd parties validated for Symantec, without keeping adequate records or controls in place.
- ploxiln 9y agoI think this is it. I think it needs to be worded: "There are 30,000 certificates which no one knows for sure the validity of, and thus need to be revalidated." The 127 merely proved that misissuance was quite possible, and did happen numerous times. EDIT: I think that's really the crux of the issue. These 127 certs which Symantec claims are "harmless" are merely the ones which were stumbled across and obviously very "how is this even possible" wrong. That's why the 30,000 is the "size of the risk". The big "Symantec" problem is that there's no good way to distinguish these 30,000 from the many more certificates issued by Symantec under different brands. For Google it's all-Symantec-or-nothing. So they're coming up with measures that apply to all-Symantec.
- richardwhiuk 9y agoAny further detail from Ryan or anyone else involved here would be very helpful (their are plenty of other organizations who bootstrap based on Google/Mozilla/Microsoft/Apple's root CA program)
- ploxiln 9y agoI think the best summary I can link to is here: https://groups.google.com/d/msg/mozilla.dev.security.policy/fyJ3EK2YOP8/gdo8kRxKEAAJ https://groups.google.com/d/msg/mozilla.dev.security.policy/... Though it doesn't mention the 30000 certs or 127 certs, it does say: (long quote from Ryan Sleevi:) In the current misissuance, my understanding is that Symantec asserts that the totality of the misissuance was related to RAs. Symantec's initial response to the set of questions posed by Google [5] indicated that " At this time we do not have evidence that warrants suspension of privileges granted to any other RA besides CrossCert" in the same message that provided the CP/CPS for other RAs besides CrossCert, and itself a follow-up to Symantec's initial response to the Mozilla community, [6], which acknowledged for the potential of audit issues in the statement "We are reviewing E&Y’s audit work, including E&Y’s detailed approach to ascertaining how CrossCert met the required control objectives.". This appears to be similar to the previous event, in that the proposed remediation was first a termination of relationship with specific individuals. However, in Symantec's most recently reply, [1], it seems that again, on the basis of browser questions from a simple cursory examination that such a statement was not consistent with the data - that is, that the full set of issues were not identified by Symantec in their initial investigation, and only upon prompting by Browsers with a specific deadline did Symantec later recognize the scope of the issues. In recognizing the scope, it was clear that the issues did not simply relate to the use of a particular RA or auditor, but also to the practices of RAs with respect to asserting things were correct when they were not. It appears that, similar to the Testing Tool's failure to ensure that certificates were adhering to the fulsome standards of authentication, Symantec's newly established compliance team was failing to perform even a cursory review of the CP, CPS, and audit statements presented - despite Symantec having found it necessary in that introspective process themselves in response to [3], as noted above. Symantec's also stated that, in response to the past misissuance, it deployed a compliance assessment tool, which functionally serves a role similar to a Validation Specialist. However, such compliance assessment was designed in a way that it could be bypassed or overridden without following appropriate policies.
- ballenf 9y agoMy take is this message was written by and for lawyers. As in, this is a coded message from Symantec to Google regarding the basis of damages upon which they will sue Google if Google doesn't backtrack. The snarky comments were probably not meant as snarky, they just happen to be the basis upon which one can seek damages from a 3rd party for damaging your business or costing you customers. I would guess that Symantec's lawyers and O-level execs are in deep discussions whether to sue regardless of Google's follow-up actions or retraction. Not saying a lawsuit would help them, but they are laying the groundwork for it here to keep their options open. And send a message to Google's legal team. Will be very interesting to see where this goes. Really hope for everyone's sake it doesn't go to court because it will just end up being a tax on users in the end (both Google's and Symantec's).
- rblatz 9y agoCan Symantec really sue google for no longer trusting them after issuing fraudulent google certs? Additionally even if they didn't and google just didn't like Symantec and decided to no longer trust them, would Symantec have any real case if they sued? I'd think not, google owes Symantec nothing.
- lazulicurio 9y agoIANAL, but it seems that one could make a passable argument for tortious interference[1]. Google isn't just affecting their B2B relationship with Symantec, they're using their share in the browser market to affect Symantec's relationship with Symantec's customers. [1] https://en.m.wikipedia.org/wiki/Tortious_interference https://en.m.wikipedia.org/wiki/Tortious_interference
- caf 9y agoThat cuts both ways, Symantec is using their share in the certificate market to affect Google's relationship with their customers.
- lazulicurio 9y ago