Slashdot Mirror


Google Details Plan To Distrust Symantec Certificates (tomshardware.com)

After deciding to distrust Symantec's certificates in March, Google has decided to release a more detailed plan for how that process will go. Tom's Hardware reports: Starting with Chrome 66 (we're now at version 61), the browser will remove trust in Symantec-issued certificates issued prior to June 1, 2016. Website operators that use Symantec certificates issued before that date should be looking to replace their certificates by April 2018, when Chrome 66 is expected to come out. Starting with Chrome 62 (next version), the built-in DevTools will also warn operators of Symantec certificates that will be distrusted in Chrome 66. After December 1, the new infrastructure managed by DigiCert will go into effect, and any new certificates issued by the old Symantec infrastructure will no longer be valid in Chrome. By November 2018, Chrome 70 will come out and will completely remove trust in all Symantec certificates that have ever been issued. Website operators can replace their old Symantec certificates with certificates from DigiCert from December 1 or from any other CA trusted by Google's Chrome browser.

140 comments

  1. Should do the same with Google certificates by Anonymous Coward · · Score: 1, Insightful

    Seriously getting tired of this company

    1. Re:Should do the same with Google certificates by Anonymous Coward · · Score: 0, Troll

      Already done. I distrusted all of Google's apps and services long ago.

      Chrome is a huge pile of shit.

    2. Re: Should do the same with Google certificates by Anonymous Coward · · Score: 0

      Been using brave

    3. Re: Should do the same with Google certificates by Anonymous Coward · · Score: 0

      Brave sucks even more than Chrome.

    4. Re: Should do the same with Google certificates by LesFerg · · Score: 2

      Brave seems a bit slow to start up and load the first page, otherwise the basic features seem to be ok.

      --
      If I had a DeLorean... I would probably only drive it from time to time.
    5. Re:Should do the same with Google certificates by Anonymous Coward · · Score: 0

      After Symantec faked Google certs? Lol.

    6. Re: Should do the same with Google certificates by negRo_slim · · Score: 1

      citation needed

      --
      On the Oregon Cost born and raised, On the beach is where I spent most of my days
    7. Re: Should do the same with Google certificates by Anonymous Coward · · Score: 0

      citation needed

      It's an opinion, so no citation is required.

      So is this:

      Google has too much power over the internet's web of "trust". Anything that they decide to deprecate (CA certs, CNs that match the hostname, etc.), is suddenly not "valid" anywhere anymore. Worse, this behavior applies to certs that are obviously not part of the major bundle. I.e. Internal CAs installed by an administrator / GP. At the same Google breaks the standard behavior of CA certs and what is considered "trusted" by hardcoding their certs.

      So no the other AC's opinion is correct in my view. Google needs to go soak it's head.

    8. Re:Should do the same with Google certificates by Anonymous Coward · · Score: 0

      Why? Because you're being force to use their free products?

    9. Re:Should do the same with Google certificates by Anonymous Coward · · Score: 0

      Seriously getting tired of this company

      Bigot!

    10. Re: Should do the same with Google certificates by LT218 · · Score: 1

      Regardless of what Google does or doesn't do correctly regarding their own certs, Symantec has nobody to blame but themselves for this one. They deserve what they're getting because they played fast and loose with the rules to make a buck.

    11. Re: Should do the same with Google certificates by Anonymous Coward · · Score: 0

      citation needed

      Here you go.

      Need more?

      Still not enough?

      Perhaps you need a little bit more?

      Or a little less?

      I hope you learned your lesson, son.

      Brave is slimeware. It's filled with all sorts of commercial bullshit like ads, tracking and monetization crap.

    12. Re:Should do the same with Google certificates by Anonymous Coward · · Score: 0

      We are their products.

  2. That's fine by Anonymous Coward · · Score: 1

    I don't trust anybody and neither should you.

    1. Re:That's fine by Paradise+Pete · · Score: 1

      I don't trust anybody and neither should you.

      I'm not buying that.

    2. Re:That's fine by Anonymous Coward · · Score: 0

      I totally do. He said not to trust anybody, so I trust him because he told me not to.

  3. Google this, Google that by Anonymous Coward · · Score: 2, Insightful

    I think it's about high time we actively start working around Google.
    Sure they used to be cool, like 20 years ago. Now they're just a powerhungy privacy eating machine and very far from doing "no evil"; they need to go.

    1. Re: Google this, Google that by Anonymous Coward · · Score: 5, Interesting

      What work around? What company or service can you use to get the information or level of service you can by using Google products? If a new privacy centric company came out and took over the world they would become Google. With all of the same privacy concerns. Even a company you started and ran. Every single person on this planet would at some point make the exact same decisions Google has along the way. Unless you never get to this size and only stay a tiny fraction of a percent of the market. Then and only then will a company care about privacy. You sacrifice privacy in the name of convenience. Without convenience you can still have privacy. With convenience comes a lack of privacy. The more convenient our lives become the less privacy there will be. In 100 years even someone like yourself or the most private paranoid person will have ZERO privacy. The only people to have privacy then will be those using NO technology of anysort. So pretty much only the few Amish who remain alive in 100 years.

    2. Re: Google this, Google that by Anonymous Coward · · Score: 0

      What services? There are no google products that anyone needs. I haven't found a requirement for one yet, although I have previously used their search engine... even that is not necessary though.
      Google is only useful to people who make themselves dependant on them for some reason.

    3. Re: Google this, Google that by gl4ss · · Score: 1

      you can use a bunch of others like duckduckgo, bing, hotmaill.. ..

      ehehehheheahahah.

      anyways, most alternatives use google parts anyways. thats a bummer.

      --
      world was created 5 seconds before this post as it is.
    4. Re: Google this, Google that by Anonymous Coward · · Score: 3, Interesting

      The company I work for uses Google for hosting emails, group discussions, videoconferencing, document management etc. I can't just opt out of using Google products and still be able to do my job.

    5. Re: Google this, Google that by Anonymous Coward · · Score: 0

      First off people should realize that privacy does not equate with anonymity. For those complaining about their privacy they have a choice. You have the choice to pick and chose which companies you are willing to provide your personal data. One example would be if I buy something from Amazon I will need to provide my name, address e-mail address, and information on my method of payment. That data is now recorded, stores, and used by Amazon to bug the hell out you by spamming your inbox with their special deals.

      On the other hand the government has access to your entire life story. Without a warrant they can walk over to the IRS and have access to your tax returns for as long as you have been filing them. This can include the address of every where you have lived. They can access your job history and every other source of your income. They know your marital history along with details on your family makeup. They will be able to see every piece of property you have bought or sold over the years. And they have the state level tax departments backing them up. The IRS makes the NSA look like amateurs when it comes to collecting and storing data on it's citizens. And the government has been collecting and storing tax payer data ever since the IRS was created.

      And Google has always been an advertising company with cool technology. Every single move Google makes is targeted towards increasing their ad revenue.

    6. Re: Google this, Google that by LesFerg · · Score: 1

      Yes but surely you wouldn't use the same identity for your work and personal life?

      --
      If I had a DeLorean... I would probably only drive it from time to time.
    7. Re: Google this, Google that by TheRaven64 · · Score: 1

      We use Microsoft's equivalents because, when it came to negotiating the license, the Google approach was take it or leave it, whereas MS worked with our IT folk to put together a contract that didn't violate any NDAs or regulatory requirements for data integrity that different departments had. The Google license was basically incompatible with any organisation that has any legal data protection requirements.

      Privacy isn't just something that's nice for individuals to have, it's an absolute requirement for a lot of businesses. If you're doing anything with medical records, then you must not share them with anyone without the correct compliance procedures in place. That's an extreme example, but most companies have commercially sensitive data. Similarly, most companies have data retention policies that require that things be deleted after a certain amount of time, but Google has no way of guaranteeing deletion (as a core part of their distributed filesystem design: deletion is implemented by simply stopping replicating some data and waiting for the drives that it's on to fail).

      --
      I am TheRaven on Soylent News
    8. Re: Google this, Google that by Anonymous Coward · · Score: 0

      I disagree. I know if a (ex?) Fortune 500 defense contracting company that uses Google apps including email across the entire organization..

    9. Re: Google this, Google that by Anonymous Coward · · Score: 0

      The one thing does not imply the other...

    10. Re: Google this, Google that by Wootery · · Score: 1

      I disagree.

      With what? That privacy is important, or that Google have inflexible terms? Be specific.

      The fact that some Fortune 500 company is trusting Google with sensitive data, doesn't mean they should be doing so.

    11. Re: Google this, Google that by Gr8Apes · · Score: 1

      And Google has always been an advertising company with cool technology. Every single move Google makes is targeted towards increasing their ad revenue.

      The only thing I take issue with there is "with cool technology". I've been forced to use their stuff. It only seems cool until you actually use it. Then the warts, boils and turds come out in force. It's almost as bad as MS tech, maybe worse these days.

      --
      The cesspool just got a check and balance.
    12. Re: Google this, Google that by chihowa · · Score: 1

      He covered that: "Google is only useful to people who make themselves dependant on them for some reason."

      --
      If you want a vision of the future, imagine a youtube comments section scrolling - forever.
    13. Re: Google this, Google that by Anonymous Coward · · Score: 0

      NSA?

    14. Re: Google this, Google that by Anonymous Coward · · Score: 0

      I disagree.

      With what? That privacy is important, or that Google have inflexible terms? Be specific.

      The fact that some Fortune 500 company is trusting Google with sensitive data, doesn't mean they should be doing so.

      He's talking about Equifax.

  4. Not worth my time. by Anonymous Coward · · Score: 0

    Google is already distrusted.

  5. Let me by Ol+Olsoc · · Score: 3, Interesting
    Tell you about Symantec.

    I was working on the computer a few nights ago, I booted it up, and started my browser. Up pops a screen, that tells me that Symantec and Arris have entered into a partnership to keep me safe from Malware.

    Hmm, that's odd. I do my own security, and it works pretty well. And I want nothing to do with Symantec.

    I try opening a few other web pages in safari and then Firefox. Same thing happens.

    Crap - I think I've been nailed. Well, I have a good backup system. It will be a PITA, but whatever.

    So before I did that, I went back and looked at the browser hijack page. I click on the "why am I seeing this?" link. I get a certificate not valid. Shit. I click on the Terms of service link. Same thing. I try a few more random pages. Nothing works. And when you can't read the terms of service, something is really wrong. So I start to re-image the machine. This will take most of my evening away.

    I call Arris to tell them of the problem. And they tell me that this is a new feature they are rolling out to select customers.

    A few seconds while I absorb this. Then I tell them that anything that has anything to do with Symantec must be removed from my computer, and removed now! I told them their "service" presents as a browser hijack, I did not and would not sign any terms that I didn't accept when I bought the router, and if it wasn't gone immediately, I would box up the router, and return it to where I bought it, with a full explanation and review of the problem. So they then had to work with Symantec to kill what they had done.

    Sorry Symantec, take your browser hijack which won't let me access any websites unless I agree to terms that I cannot see, and bend over, and shove it up your anus as far as you can, using a pincone, then a baseball bat, and after that, a dildo covered with sandpaper.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    1. Re:Let me by StikyPad · · Score: 4, Informative

      This isn't anything "on your computer," it's MITM javascript injection by your ISP. You didn't need to reimage your computer (and, in fact, that's unlikely to change anything), rather you need to opt-out, since they decided to opt you in. Also, you should probably either up your technical proficiency, or else stop "doing your own security."

      WTF, this is supposed to be a site for nerds. It says so right there at the top.

    2. Re:Let me by sgage · · Score: 1

      You forgot the rough corn cob...

    3. Re:Let me by Anonymous Coward · · Score: 1

      "bend over, and shove it up your anus as far as you can, using a pincone, then a baseball bat, and after that, a dildo covered with sandpaper. "

      Ok we get it! Did you really have to go into such detail? Some of us are at work and it gets real embarrassing to pop a boner in front of everyone.... Geez.

    4. Re:Let me by jonnythan · · Score: 3, Funny

      I suppose being a nerd doesn't mean you actually know anything...

    5. Re:Let me by Anonymous Coward · · Score: 0

      So I start to re-image the machine. This will take most of my evening away.

      LOL. WTF. I can restore my computer from a backup image in ~10 minutes. That's not theory. I've actually done it.

    6. Re:Let me by sinij · · Score: 5, Insightful

      Seeing browser hijack and concluding your machine was pwned isn't unreasonable. Injection by ISP is such sacrilege that it isn't something most techies would check as the first step.

    7. Re:Let me by connect4 · · Score: 1

      +1, the grandparent is an asshole

    8. Re:Let me by Anonymous Coward · · Score: 0

      Maybe they're reimaging from the "cloud". Also, they may have some programs they need to manually reinstall for whatever reason.

    9. Re:Let me by Anonymous Coward · · Score: 0

      Cry moar.

    10. Re:Let me by llamahunter · · Score: 1

      So, how do you really feel about Symantec?

    11. Re: Let me by Anonymous Coward · · Score: 0

      I can understand it taking the evening myself. But I highly doubt anyone here is dumb enough to store data in "the cloud"

    12. Re:Let me by DNS-and-BIND · · Score: 1

      Much like Google removed its "Don't be Evil" motto when they rebranded into Alphabet, Slashdot removed the "News for Nerds" motto some years ago. Now it's just a property of dice.com or whoever the hell owns it now.

      You can see on the front page, comments barely go into triple digits any more. Slashdot is a shell, and I don't know why I keep coming here. Habits are hard to break.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    13. Re:Let me by DNS-and-BIND · · Score: 2

      It's commonplace in other parts of the world, China, India, Philippines, etc. They'll not only inject ads into your browsing session, but on mobile they'll put one of those Apple-style floating circles in the corner, to "help" you.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    14. Re:Let me by Anonymous Coward · · Score: 2, Insightful

      You called Arris? Arris doesn't do MITM, they do hardware. Your ISP does MITM. Time Warner (now Spectrum), Cox, Xfinity, or whatever, is your ISP. That's who you call. Also, Arris is in bed with McAfee, not Symantec. Are you using your ISPs DNS servers on your router? STOP DOING THAT IMMEDIATELY! Use OpenDNS, or Comodo, or Level3, or anything else! If you still see anything off, use a VPN.

    15. Re:Let me by chuckugly · · Score: 2

      You don't know how computers work, go play in reddit.

    16. Re:Let me by Anonymous Coward · · Score: 2, Interesting

      As a security guy, I have found nearly all software designers, architects, "engineers", CS professionals, whatever they wish to call themselves to be little better than a gadget enthusiast when it comes to security. They are taught an attitude by many and reinforced by each other that knowing one level or area of information technology makes them competent at every aspect. It's like a physicist believing they are just as good as a chemist at chemistry because it's all physics in the end anyway.

      They are wrong. That's why an average system needs dozens of weekly patches. That's why modern software still falls victim to the same old exploits. That is why my field exists.

      So I should probably give thanks for security incompetence to be the norm among even the most veteran programmers.

    17. Re:Let me by Anonymous Coward · · Score: 0

      Injection by ISP is such sacrilege that it isn't something most techies would check as the first step.

      Perhaps not as the first step, but seriously who browses without a VPN anymore? Especially after Trump lowered the boom on net neutrality and then did it one better by explicitly allowing ISPs to track and sell your browsing to advertisers. Browsing without a VPN anymore is like picking up bar girls in Manila without a condom, you just don't do it.

    18. Re:Let me by phantomfive · · Score: 4, Informative

      You shouldn't have an Arris modem anyway. They are back-doored, with hard-coded credentials. Arris security makes Equifax look like Fort Knox.

      --
      "First they came for the slanderers and i said nothing."
    19. Re: Let me by Anonymous Coward · · Score: 0

      10 minutes you say? Unless you get the dreaded R Tape loading error, 0:1. Always test your backups.

    20. Re: Let me by Anonymous Coward · · Score: 0

      I'm afraid Slashdot is precisely the right place for people who don't know how computers work. It has been for some time now; merely choose a faction from one or more of: poseurs, Dunning-Kruger children, Nazis, Russian state trolls, or sociopaths masquerading as autists.

    21. Re: Let me by Anonymous Coward · · Score: 0

      My apologies, I totally missed out Inpatients of the Nietzsche-Rand memorial ward. This will not affect their regular medication.

    22. Re:Let me by TheRaven64 · · Score: 2

      10 minutes? My laptop's SSD can manage 300MB/s sustained writes on a good day. Ten minutes is enough to write 175GB. The drive is 1TB and about 900GB is used. Assuming that I had the data in a form that I could just stream to the disk without the FS getting in the way, it would take around 50 minutes, and that's assuming that the SSD could actually sustain that write speed for that long (it can't). Either your system disk and your backups are NVMe, or you don't have much data on your computer...

      --
      I am TheRaven on Soylent News
    23. Re: Let me by Anonymous Coward · · Score: 0

      Yeah, Trump's net neutrality stance (that hasn't taken effect) is totally more threatening than Obama turning the entire Intelligence complex against it's own citizens...

    24. Re:Let me by Big+Hairy+Ian · · Score: 1
      --

      Build a Man a Fire, and He'll Be Warm for a Day. Set a Man on Fire, and He'll Be Warm for the Rest of His Life.

    25. Re: Let me by Anonymous Coward · · Score: 0

      Obama didn't stop it, Bush started it. Patriot act, remember?

    26. Re:Let me by AmiMoJo · · Score: 2

      ISPs have been screwing to HTTP for over a decade around here. When I have issues the first thing I check is if I'm not connected to my VPN for some reason, and if I get the same result on a mobile connection. I've never had to go beyond checking those two so far.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    27. Re:Let me by Anonymous Coward · · Score: 0

      Wait till you see Indonesia. It's the default state for isp to mitm.

    28. Re:Let me by Holi · · Score: 1

      Or change your DNS servers

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    29. Re: Let me by Anonymous Coward · · Score: 0

      Obama did nothing to stop 9/11 just as he didn't act quickly enough to help the victims of Katrina. All hail President Trump!

    30. Re:Let me by Holi · · Score: 1

      Cable companies using DNS redirects isn't something you expect? That's been the norm for years now.

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    31. Re: Let me by Anonymous Coward · · Score: 0

      How did you conclude it's the ISP? If Symantec and Arris enter into a partnership it's even possible you got bum router firmware from Arris.

      In a world where every device can be updated automatically at any time, any device can be updated at any time.

      But thanks for the correction.

    32. Re:Let me by Gr8Apes · · Score: 1

      yep, started running my own DNS setup to completely ignore my ISP. Their stupidity continues.

      --
      The cesspool just got a check and balance.
    33. Re:Let me by Gr8Apes · · Score: 1

      Much like Google removed its "Don't be Evil" motto when they rebranded into Alphabet,

      Google effectively toilet papered its "Don't be Evil" motto when it went public in 2004.

      --
      The cesspool just got a check and balance.
    34. Re:Let me by chihowa · · Score: 1

      Which was really a pretty sketchy motto to begin with. Who has to remind themselves not to be evil so much that it becomes a motto?

      --
      If you want a vision of the future, imagine a youtube comments section scrolling - forever.
    35. Re:Let me by Bob+the+Super+Hamste · · Score: 1

      Not bad enough. I'm thinking the dildo from Seven

      --
      Time to offend someone
    36. Re:Let me by dkone · · Score: 1

      You say that like it is an insult. The real joke is on you though. Slashdot is a mere shell of what it once was. Given the choice between the two, Reddit is going to win.

      DK

    37. Re:Let me by Anonymous Coward · · Score: 0

      Seeing browser hijack and concluding your machine was pwned isn't unreasonable. Injection by ISP is such sacrilege that it isn't something most techies would check as the first step.

      He's not a techie. Read his post again.

      Then I tell them that anything that has anything to do with Symantec must be removed from my computer, and removed now!

      This sounds more like a raving old man on a Windows machine. Maybe a Mac - he did mention Safari.

    38. Re:Let me by Anonymous Coward · · Score: 0

      You shouldn't have an Arris modem anyway. They are back-doored, with hard-coded credentials. Arris security makes Equifax look like Fort Knox.

      I'm in the Triangle area (NC) and use AT&T. My other option is Charter (aka TimeWarner) - which I dropped years ago because of their shenanigans.

      No, I don't want to use an Arris modem. The problem is, AT&T does not allow you to purchase and use your own modem for Uverse. You MUST rent a modem from them, and you MUST pay the monthly rental fee. This doesn't leave me many (any?) options to escape the compromised Arris modem.

    39. Re:Let me by Gr8Apes · · Score: 1

      Not really that sketchy, IMHO, as when they started it was just a search engine, not an ad serving platform.

      --
      The cesspool just got a check and balance.
    40. Re:Let me by chuckugly · · Score: 1

      You are probably right.

    41. Re:Let me by Anonymous Coward · · Score: 0

      The sketchy part is that they had to continuously tell themselves not to be evil, which indicates that being evil is their natural state and it takes conscious effort to not be evil. The fact that they couldn't seem to do too much damage back in the day isn't much of a consolation, especially since they've dropped the motto now that they can really do damage.

      I don't know if many people would feel too comfortable walking down a dark alley alone with somebody muttering, "Don't murder people," to themselves continuously. Having "Don't be evil" as a motto is like walking around wearing a shirt that says, "Totally not a rapist."

    42. Re:Let me by Anonymous Coward · · Score: 0

      Exactly, and what is a nerd if not a know-it-all? People on this site who've never even been outside have a very strong opinion on the latest climatological research. We exemplify dunning-kruger.

    43. Re:Let me by Ol+Olsoc · · Score: 1

      Both the rough corncob and the dildo fromSeven is good!

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    44. Re:Let me by Ol+Olsoc · · Score: 1

      This isn't anything "on your computer," it's MITM javascript injection by your ISP. You didn't need to reimage your computer (and, in fact, that's unlikely to change anything), rather you need to opt-out, since they decided to opt you in. Also, you should probably either up your technical proficiency, or else stop "doing your own security."

      WTF, this is supposed to be a site for nerds. It says so right there at the top.

      Oh, dear, I'm getting a lecture. Lookie fellow, this transpired over time, and it was rather shocking that even McAffee, who don't have a lot of ethics to begin with, would hijack a browser.

      I'd have to first Know that McAffee and Arris had entered into this unholy matrimony, Then I'd have to not be suspicious of of links that gave me 1, bad certificates ( perhaps you as a self acknowledged genius like bad certificates) and the other link for the TOS, didn't show me anything.

      What they may or may not have had on my computer is irrelevant as week old smegma. If anything was there, it needed to go, The point is that all of my traffic was getting redirected and McAffee was then making a determination as to whether I could see it or not.

      So the computer gets re-imaged regardless, because I don't trust McAfee, and this little trick didn't make me feel warm and fuzzy either.

      But hey, you just click on the only link that would allow you to continue internet accss, and don't worry about the TOS that it doesn't allow you to see - sounds like expert level computer savvy to me. In the meantime, I've inherited 10 million USD, and need you to open an account in the Netherlands to deposit money for the unfortunate bribes that must be made to conduct business. So if you would please open the account, and deposit the amount of 10,000 dollars USA, you will be richly rewarded when the total amount of money comes through.

      Yours in Christ Jesus, Barrister Mutambo Ngumbo

      Sounds legit.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    45. Re:Let me by Ol+Olsoc · · Score: 1

      Seeing browser hijack and concluding your machine was pwned isn't unreasonable. Injection by ISP is such sacrilege that it isn't something most techies would check as the first step.

      Exactly. https://en.wikipedia.org/wiki/... It is not unusual for a hijack to also install a keylogger, so at the time, this happened, I wasn't for certain that I wasn't totally pwned. Seriously unethical, and regardless, I had no internet access unless I either called Arris and got the shit turned off, or clicky clicky on a mysterious link that would install or do gawd knows what.

      What is a little surprising is self acknowledged experts who seem to think otherwise. I personally am interested in their motives.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    46. Re:Let me by Bob+the+Super+Hamste · · Score: 1

      I'll accept that.

      --
      Time to offend someone
    47. Re:Let me by Ol+Olsoc · · Score: 1

      As a security guy, I have found nearly all software designers, architects, "engineers", CS professionals, whatever they wish to call themselves to be little better than a gadget enthusiast when it comes to security. They are taught an attitude by many and reinforced by each other that knowing one level or area of information technology makes them competent at every aspect. It's like a physicist believing they are just as good as a chemist at chemistry because it's all physics in the end anyway.

      They are wrong. That's why an average system needs dozens of weekly patches. That's why modern software still falls victim to the same old exploits. That is why my field exists.

      So I should probably give thanks for security incompetence to be the norm among even the most veteran programmers.

      Okay, since all of the experts here on Slashdot are pillorying my for my stupidity, now that I have a security professional, I'd like a security professional's answer.

      You are sitting at a computer that has been functioning properly for a long time. Typical security procedures, an anti-virus, regular updates, firewall both on the computer and on the router.

      Now, instead of any internet access, when you open a browser, you get one screen only. An announcement that the router you are using's manufacturer and a sketchy internet security company have entered into a partnership to protect you.

      Three links on the page. Two do not work, or to be more precise a 400, with a bad certificate?

      Opening more tabs or windows gives you another screen like the first one. Bookmarks and typed URL's give you the same page. Nothing gets rid of the page that demands you click on a link to get internet access. Keeps coming back like Chucky.

      As a security professional, do you recommend clicking on the third link that they declare will give you internet access again? You will apparently get internet access again, but will you get anything else?

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    48. Re: Let me by Ol+Olsoc · · Score: 1

      How did you conclude it's the ISP? If Symantec and Arris enter into a partnership it's even possible you got bum router firmware from Arris.

      In a world where every device can be updated automatically at any time, any device can be updated at any time.

      But thanks for the correction.

      It wasn't the ISP. It was Arris and Symantec. But that was only confirmed by contacting Arris, and later Symantec.

      I wonder if slashdotters think that any webpage they go to is legit. If so, it brings some understanding to the number of security breaches like Equifax et al. Security like that is hard to find. Or not.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    49. Re:Let me by Ol+Olsoc · · Score: 1

      You don't know how computers work, go play in reddit.

      Oh yes, I'm the dumbest asshole on the planet.

      Tell me, if you lost internet access, and the only way you could get it back was to click on the only webpage that showed up, would you without hesitation, click on that link? You either have no access, call the people who are presumably the ones who did this to you, or click the link.

      If you answer anything other than you contact the people responsible, you have absolutely no place telling me I know nothing, and frankly, you need to stick to surfing shemale midget scat porn and posting on facebook, Chuckugly.

      You are Dunning- Kruger personified.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    50. Re:Let me by chuckugly · · Score: 1

      I'd use check my router IP settings and then use ping and traceroute to start with, just to see what's going on. If you think not having access to the world wide web is the same as losing internet access you really should stick to something less technical.

    51. Re:Let me by Ol+Olsoc · · Score: 1

      I'd use check my router IP settings and then use ping and traceroute to start with, just to see what's going on. If you think not having access to the world wide web is the same as losing internet access you really should stick to something less technical.

      So anyhow, you would not have engaged in communications with the people who claimed to have enabled this? Elucidate, and instead of being a slashdot genius, tell me why I should not have.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    52. Re:Let me by chuckugly · · Score: 1

      You asked the router manufacturer (Arris) to "remove the Symantec from your computer", and then you reimage your PC when someone tries to MitM you? If that actually makes sense to you then I stand by everything I've said.

      It's cool if you don't want to know how the stuff you use works, I bet almost no one knows how all the stuff they use works, there is a lot of technology in use today. But this is supposed to be a technical site; different standards. And no, I would not have called Arris, but then I don't use the crap modem or router the ISP supplies either.

      In other news, McAfee are the ones who actually have a deal with Arris to supply a secured router, Symantec makes their own secure router, and sells it via Best Buy and Amazon, among other stores. I would strongly suspect the culprit was your ISP or some flakey browser addon. Consider not using the ISP DNS servers, and learning to use tools like ping and tracert, they are pretty simple and can shed a lot of light on simple problems.

    53. Re:Let me by Ol+Olsoc · · Score: 1

      You asked the router manufacturer (Arris) to "remove the Symantec from your computer", and then you reimage your PC when someone tries to MitM you? If that actually makes sense to you then I stand by everything I've said.

      No, actually I did not. say tha. You might think that you are smarter than me in all ways, but what I wrote, and which for some unknown reason you lied about is:

      "Then I tell them that anything that has anything to do with Symantec must be removed from my computer, and removed now!

      That is cut and pasted from my post. You can put that in quotes. Not what you did. Because what you put in quotes was untrue.

      An unreasonable request? I did not know at the time if "anything" that had anything to do with Symanec was there, but if anything was, it had to go. Not a reasonable demand? As the smart internet guy, was the presence of any Symantec installed software impossible? Explain. Not that I'd believe you now, because you'll just make shit up. That's what happens when you lie. Not much lower in my book than someone who is a liar.

      If someone came to you as a security IT guy with those symptoms, you would not inspect the computer to see if anything had been installed on it? Wouldn't even wonder because you knew already that there was none? Just bloviate about how smart you are? Would you bet your job on it? In some places you would lose it. Anyhow, no need to respond, because I don't believe anything proven

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    54. Re:Let me by chuckugly · · Score: 1

      Yeah, it was paraphrased. The facts presented are the same.

      Yes, it's unreasonable to ask a router OEM to alter the configuration of your PC unless you have some sort of contract with them.

      My first suspicion given the very limited info you have provided is that your browser traffic was being routed through some sort of sandboxing and/or deep inspection proxy, but I can't be sure without actually having a look. The agency being used to implement that redirection could be many places but most likely it's something you installed, intentionally or not.

      Your complete lack of a clue as to what exactly was going on tells me that either it was not implemented locally, or you are completely clueless. I prefer to think maybe it was something done in your router and you are mentally competent, which makes me recommend you stop letting 3rd parties control your router. In any case, no, I'd not call the OEM, nor would I reimage my PC. That would be idiotic.

    55. Re:Let me by Anonymous Coward · · Score: 0

      Yeah, here too. They inject some sort of javascript. On desktop it's easy to solve, just put some domains to host file, or use JS blocker add-on (noscript, umatrix, etc) for browser. On mobile device it's harder to solve. Well, one can always use VPN I suppose.

    56. Re:Let me by Anonymous Coward · · Score: 0

      Changing DNS server won't do much if the page is served with plain HTTP. Also it's quite common around here for ISP to proxy DNS. One of the solution is to change DNS to secure one (DNScrypt, etc) and request HTTPS version of the page, if HTTPS is not available then this solution won't work. The ultimate solution is using VPN, but it will raise a red flag.

    57. Re:Let me by Anonymous Coward · · Score: 0

      I'd like to note that absolutely nothing in your post hints towards that you are actually a competent security professional with a clue how things are actually supposed to be done. All you did was throw some shit around other incompetent posers but they can do that themselves just as well.

    58. Re:Let me by Anonymous Coward · · Score: 0

      Well there's a chance that "restoring from an image" means swapping a hard drive to another;)

    59. Re:Let me by Anonymous Coward · · Score: 0

      You mean you'd use a potentially compromized machine to access your router, possibly expanding the attack further?

      Thanks, tech expert.;)

    60. Re: Let me by Brockmire · · Score: 1

      If you didn't install or change any software yourself, yes, troubleshooting as a DNS issue would be first priority. Wouldn't you want to find out how the mysterious infection occurred before reimaging and having it reinfected? Seriously, this was poor troubleshooting. Do you freak out the first time signing into a hotel hotspot with walled garden redirect? If not, you're smarter than OP.

  6. What about Firefox? by Anonymous Coward · · Score: 4, Interesting

    What's Mozilla's plan? Are they going to continue to trust the old certs?

    1. Re:What about Firefox? by Anonymous Coward · · Score: 1

      Their lets-just-copy-whatever-chrome-does -management team goes to Hawaii for some strategy meetings that take a week and concludes that while they do not understand why chrome did some change, they will copy that change anyway.

    2. Re:What about Firefox? by sasparillascott · · Score: 1

      They're planning on matching Google's plan: https://www.thesslstore.com/bl...

      Sure is alot of nasty replies in the field here today. You'd almost wonder if someone else (competitor) was mounting a sponsored campaign to tear down the site.

  7. TRUST is supreme by swell · · Score: 4, Interesting

    Many businesses have only one feature to support their business model: TRUST. Symantec is one. Equifax another. All the financial firms: Merrill Lynch, Wells Fargo, B of A... Some manufacturers: Volkswagen, Gerber baby products, Mylan pharmaceuticals... Many of these and more have disgraced themselves at some time and somehow survived; the others are forgotten.

    They may have many products & services, or only a few, but without TRUST they have nothing.

    --
    ...omphaloskepsis often...
    1. Re:TRUST is supreme by Sloppy · · Score: 1

      One of the problems that PGP solved a quarter century ago, was understanding that it's hard/foolish to put all your eggs in one basket. Trust is a matter of degrees. It's batshit insane that our trust levels are "I completely trust you, absolutely" and "I don't trust you at all." In real life, you almost never use the former, and you trivially upgrade from the latter (but almost never all the way up to the former!).

      When an introducer is sort of trusted, and sort of not, it should be entered that way and handled that way. And you should have multiple introducers, to make up for the fact that you can't possibly trust any of them completely (and also the fact that your trust opinions change). Losing a popular CA should have minimal impact, provided that each identity is certified by several others.

      Yet we still don't use this level of tech on the web, even though it (barely) pre-dates the web.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    2. Re:TRUST is supreme by Anonymous Coward · · Score: 0

      Volkswagen, "somehow survived"? Funny you should include them as an example--not only have they "survived", looking at their recent reported sales, you'd think nothing bad had ever happened to them.

    3. Re:TRUST is supreme by deesine · · Score: 1

      "disgraced themselves at some time and somehow survived"

      They survived because for a large number of people trust isn't supreme: they are liars, they lie to themselves and to others, and when liars discover that a company they use has lied, well, deep down they know it's not that bad. They like their Volkswagen, nay love their Volkswagen, and so internal logic concludes it's not worth changing car companies over some lie that hardly affected them. For these people, and to an extent all people, trust is set right next to convenience and perception of worth.

      --
      damaged by dogma
    4. Re:TRUST is supreme by HiThere · · Score: 1

      When it comes to car companies, why did you single out Volkswagen? They weren't the only one to cheat on the tests, most of the companies have been found to have done so since then. They were just the first one discovered. Or were you thinking of something else.

      With cars, I would have picked Ford for the "Ford firebomb" otherwise known as the Pinto.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    5. Re:TRUST is supreme by goose-incarnated · · Score: 1

      Many businesses have only one feature to support their business model: TRUST. Symantec is one. Equifax another. All the financial firms: Merrill Lynch, Wells Fargo, B of A... Some manufacturers: Volkswagen, Gerber baby products, Mylan pharmaceuticals... Many of these and more have disgraced themselves at some time and somehow survived; the others are forgotten.

      They may have many products & services, or only a few, but without TRUST they have nothing.

      I think just about every single company you've listed proves your point wrong - we have seen time and time again that companies who lose the trust of their userbase still manage to stay in business, sometimes even thrive.

      Companies have proven in practice that without TRUST it'll still be business as usual.

      --
      I'm a minority race. Save your vitriol for white people.
  8. Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL by Anonymous Coward · · Score: 0

    that's a LOT of fucking certificates that google is going to shit on.

  9. Good, let's distrust these lying sacks by guruevi · · Score: 4, Informative

    Basically, what happened is that Symantec allowed "foreign entities" (in countries like China, Italy, Brazil, Korea, Japan, Spain etc) to create certificates using it's root certificate.

    Initially someone pointed out that they were just signing a bunch of test domains that were actually registered but both internal and external audits eventually found that they had delegated signing through cross-certificates to various banks and telecom agencies and ~30,000 certs were being issued by these "Regional Authorities" including google.com and various of it's subdomains.

    Symantec has proven to not be trustworthy, initially it appeared to whitelist NSA malware, now we see that it's just giving away signing authority to international agencies and governments.

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
    1. Re:Good, let's distrust these lying sacks by rudy_wayne · · Score: 3, Informative

      Here's the real problem:

      By November 2018, Chrome 70 will come out and will completely remove trust in all Symantec certificates that have ever been issued.

      Waiting a year is bullshit. All Symantec certs should be distrusted effective November 1 of this year, not next year. If you can't get a new cert in 30-45 days you don't really give a shit and your website shouldn't be trusted.

    2. Re:Good, let's distrust these lying sacks by sinij · · Score: 4, Informative

      While agree that Symantec should be taken behind a shed and shot right away, if we do it this way ricochet will hurt a lot of innocent businesses that have nothing to do with this. Year gives them barely enough time to move out of the way.

    3. Re:Good, let's distrust these lying sacks by Anonymous Coward · · Score: 0

      wish i could upvote for truth

    4. Re:Good, let's distrust these lying sacks by TheRaven64 · · Score: 1

      A year seems a long time. I'd start by immediately downgrading all EV certs from Symantec to normal certs. Then, a month later, remove the padlock icon entirely and treat them as if they were HTTP. Two months after that, distrust them entirely.

      As for those innocent businesses: they were sold a cert by Symantec with 'accepted by all major browsers' in the advertising. They're going to get a full refund (and if they don't, you can bet that the class action suit will hurt Symantec more than giving refunds). If there's a rush to switch, you can bet that there are a lot of CAs that would give a discount for the first year for existing Symantec customers.

      --
      I am TheRaven on Soylent News
    5. Re: Good, let's distrust these lying sacks by Anonymous Coward · · Score: 0

      Penis envy detected.

    6. Re:Good, let's distrust these lying sacks by thegarbz · · Score: 1

      If you can't get a new cert in 30-45 days you don't really give a shit and your website shouldn't be trusted.

      You're talking from the perspective of a company where the website is an active and maintained part of their strategy. There are many for which a website is nothing more than a tool, many small shops with small online shopping carts, completely 3rd party outsourced IT where this will do no more than cause them additional expense assuming they are aware of the issue at all before the entire site goes down the red warning hole.

    7. Re:Good, let's distrust these lying sacks by AmiMoJo · · Score: 1

      It would be better to let the customers get hurt I'm afraid. They can sue Symantec for any costs or lost revenue. If it's that critical then Symantec should have had indemnity insurance and the customers should have had insurance.

      Don't forget, the consequence of delaying is that innocent people can be victimized with bad Symantec certificates. There is no option that avoids harming anyone.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    8. Re: Good, let's distrust these lying sacks by Anonymous Coward · · Score: 0

      Yeah, those 2 inch penises are something to behold.

    9. Re:Good, let's distrust these lying sacks by edtice1559 · · Score: 1

      You can remove the Symantec root CA now if you prefer.

    10. Re:Good, let's distrust these lying sacks by Anonymous Coward · · Score: 0

      So their poor business management becomes our problem? If there was a recall on some electrical system in their building that could start a fire, should they get a pass on replacing it because it's not an active and maintained part of their strategy?

      If they need the site to stay up to remain in business then they need to be able to deal with issues like this. Otherwise, they can just take their time and fix it at their leisure.

    11. Re: Good, let's distrust these lying sacks by Anonymous Coward · · Score: 0

      Checked out a lot of them did you? Purely in the service of your eugenics research though, I'm sure.

  10. Re:Thawte, VeriSign, Equifax, GeoTrust, and RapidS by Anonymous Coward · · Score: 0

    Good. Fuck 'em.

  11. No wonder there are no Trump certificates. by Anonymous Coward · · Score: 0

    Bing bong.

  12. Too Slow by crow · · Score: 4, Informative

    They should have done this much faster. Once they decided there was a problem, tell people they have 90 days to get a new certificate. What's the big deal? For most purposes, a free one from Let's Encrypt is good enough (it shows up in the browser as trusted--what more do you want?).

    There was no reason to give Verisign enough time to salvage their business and sell it off instead of just killing them the way they should have been.

    1. Re:Too Slow by Anonymous Coward · · Score: 0

      Enterprise applications, Enterprise trust certificates, process changes. Yeah, who cares about a giant section of the user community.

      Let's encrypt is good enough for people with an airgap.

      This had *nothing* to do with being kind to Symantec and the old Verisign business, it's all to do with giving users a chance to update their environment before everything breaks.

    2. Re:Too Slow by phantomfive · · Score: 2

      If you want to, you can remove it from your own browser.

      --
      "First they came for the slanderers and i said nothing."
    3. Re:Too Slow by TheRaven64 · · Score: 1

      Symantec doesn't do free certs, so no one is likely to be using them for non-commercial sites where Let's Encrypt would be appropriate. Most of their business is in the form of EV Certs. The process of applying for an EV certificate can take several weeks, once you've picked the replacement provider, because there are several round trips of paperwork. 90 days is probably long enough, but it's cutting it a bit fine for a lot of people.

      --
      I am TheRaven on Soylent News
    4. Re:Too Slow by Anonymous Coward · · Score: 0

      EV Certs are just another way of tricking users into believing that a site is "serious", for some definition of seriousness. They should be banned by all browsers.

    5. Re:Too Slow by scdeimos · · Score: 0

      For most purposes, a free one from Let's Encrypt is good enough (it shows up in the browser as trusted--what more do you want?).

      Why exactly is Let's Encrypt actually good enough? How is Let's Encrypt any better than StartSSL - which has already had its trust revoked?

      Current initiatives of major browser developers such as Mozilla and Google to deprecate unencrypted HTTP are counting on the availability of Let's Encrypt. - Wikipedia

      Which is extremely humorous considering that Let's Encrypt requires tcp/80 to be open for ACME (Automated Certificate Management Environment) to verify the initial identity of the host name being requested. By requiring tcp/80 to be open you're doubling the attack surface of something that could have only needed tcp/443.

    6. Re:Too Slow by jawtheshark · · Score: 1

      Personally, I feel that LetEncrypt should only allow verification using TXT entries in the DNS. Apparently it can do that too, but it's not the default.

      --
      Ahhh...the great dumpster continuum. Many a free computer will be found there. -- sowth (748135)
    7. Re: Too Slow by Anonymous Coward · · Score: 0

      StartSSL wasn't distrusted because they issued free certificates. It was distrusted because the owner changed to a Chinese entity known to issue fake (i.e. issue certificate to someone to owning the domain) and/or backdated certificates.

    8. Re:Too Slow by TheRaven64 · · Score: 1

      EV certs show that the CA has performed some validation that the certificate is associated with a specific organisation, not just with a domain name. It's how you know that the cert for paypal.com is owned by PayPal Inc. and the domain for paypal.scammer.com is not.

      --
      I am TheRaven on Soylent News
    9. Re:Too Slow by Anonymous Coward · · Score: 0

      Normally I'd agree, but hijacking DNS is too easy still.

    10. Re:Too Slow by guruevi · · Score: 1

      Let's Encrypt so far hasn't yet gotten their hands caught in the cookie jar and they are infinitely more transparent than most paid cert providers. Certificate providers in general do not put up a public ledger of all certificates it has signed, they barely even verify whether you are the owner of a domain and/or site. LE at least requires valid domain setups and unless you've been rooted (at which all bets are off regardless of your CA) you have to put up a challenge to make sure you can renew and certs are short enough in length that it both encourages automation and reduces the timespan attackers have to attack the weaker protocols.

      The rest of your post is BS - you can do LetsEncrypt specifically via HTTPS (TLS-SNI-01 challenge which is described in the RFC) and most places have port 80 forwarded to port 443 being handled by the same daemon (apache or nginx) but it's also entirely possible to set up your own ACME CA protocol for internal usage or that uses alternative methods of verification.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    11. Re:Too Slow by Anonymous Coward · · Score: 0

      Symantec doesn't do free certs, so no one is likely to be using them for non-commercial sites where Let's Encrypt would be appropriate. Most of their business is in the form of EV Certs. The process of applying for an EV certificate can take several weeks, once you've picked the replacement provider, because there are several round trips of paperwork. 90 days is probably long enough, but it's cutting it a bit fine for a lot of people.

      But let's be honest here. Anyone that was dumb enough to give Symantec money kind of deserves to suddenly find their EV cert untrusted.

    12. Re:Too Slow by Sloppy · · Score: 1

      This had *nothing* to do with being kind to Symantec and the old Verisign business, it's all to do with giving users a chance to update their environment before everything breaks.

      If an untrusted cert breaks things, then the user's browser is defective.

      It should work, but the UI should indicate that it's not totally sure who the user is connected to. That's ok to do, because it's true. (An untrusted cert should never, ever have any negative consequences or keep things from working if the user so chooses; it should just have a lack of positive consequences.)

      If we are still using defective browsers, then it is good to break things now, so that we'll have incentive to fix the browsers. Otherwise, this is going to keep happening whenever CAs fuck up.

      We are institutionalizing CA unaccountability by saying "it needs to keep looking good" is more important than "it needs to accurately reflect how sure we are."

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    13. Re:Too Slow by jawtheshark · · Score: 1

      If you can hijack DNS, you can point it to a host under your control and do the verification with LetEncrypt using the current system. The current system doesn't protect you at all from DNS hijacking.

      --
      Ahhh...the great dumpster continuum. Many a free computer will be found there. -- sowth (748135)
  13. Wow, nice logic by Anonymous Coward · · Score: 0

    Because Symantec started doing dodgy things with certs and malware, google are removing them.

    This is good, and it improves your privacy and security, and only dickhead would distrust google because of this.

    Go stick your head back in the ground, and think and maybe even understand why google have done this before you make comments that would be seen as idiotic, stupid, and clearly a fine display of fuckwittery from anyone that berates google for this.

  14. What great timing by Holi · · Score: 2

    My company just purchased new 3 year certs from Symantec.

    --
    Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    1. Re:What great timing by dkone · · Score: 1

      On the converse, our company will be dropping Symantec AV in less than a month (which means we will have zero Symantec on our network). No more SEPM server, I really don't like using it. It is a huge PITA.

  15. Windows Phone by tepples · · Score: 1

    We use Microsoft's equivalents

    Including Microsoft's purported equivalent to Android? If so, how did you manage your migration from Windows Phone when Microsoft announced its end of life?

    1. Re:Windows Phone by TheRaven64 · · Score: 1

      Nope, just the Office 365 stuff (and their associated cloud file store thingy). I don't use it personally (except to get the bundled version of PowerPoint, because DARPA does so love PowerPoint slide decks), but it's popular in some other departments. My understanding is that the Android and iOS versions of Office give you a fairly seamless transition from their Windows Phone equivalents: just log in with the credentials and all of your files is available. We don't use their mail system, because our mail admins have been running our internal email system since before email went over the Internet and have more experience than any cloud provider is likely to have.

      --
      I am TheRaven on Soylent News