Slashdot Mirror


Thawte Bought by Verisign

ChrisKnight was of the many people that wrote with the story on news.com that VeriSign has purchased Thatwe Consulting. Purchase price was reportedly $575 million, although the deal must still be approved.

123 comments

  1. Re:hello monopoly by DJerman · · Score: 1
    I am not a mozilla contributor (but I read about it on the web).

    AFAICT, there is no crypto in Mozilla due to the international nature of the dev. effort. There is a separate crypto project, and no doubt Netscape will add a crypto module if the Mozilla product becomes Navigator 5.0. No crypto => no CA. For Netscape > 4.5 there are some Verisign CA certs that expire in 1999, but some are good to 2028, so it depends on your host's cert (which may expire).

    --
  2. Re:Darn! by um...+Lucas · · Score: 2

    On overpriced-scames....

    You can go ahead and create your own keys and certificates... What you're paying Verisign for is not 100% related to your keys.

    First, you're paying to have a certificate that's been signed by an authority that just happens to be preinstalled in 99% of the browsers out there.

    You're also paying for the "trust" factor that goes into getting a certificate. Yeah, the lowerst level ones aren't much more than filling out paperwork, but (AFAIK) in order to get one of the more expensive ones, you must go through more steps to establish "who" you are.

    If all you want is to establish secure connections, you don't need either of their services. If you want to be able to do so without having a little warning pop up on a users screen, you need to enlist their services.

    That all said, if the merger/acquisition goes through, close attention should be paid to their pricing... If they immediately yank the low-cost certificates, or even if it's an eventual thing, a big stink will need to be made IMMEDIATLEY...

    Until then, though... More power to them.

  3. Re:Worth the money or not? by Anonymous Coward · · Score: 0

    market position, Oh you mean they need to be microsofts bitch.

  4. Noooooooooooo! by Anonymous Coward · · Score: 0

    The spam - the spam! I switched to Thawte because Verisign insisted on spamming us. I then changes all the profiles (about half a dozen including personal certs and code signing certs) to say "don't spam me ever", and the cretins still spammed. Now Verisign are going to acquire me as a customer against my will! Fuck that - we need a Slashdot CA.

    1. Re:Noooooooooooo! by mlesesky · · Score: 1

      Slashdot CA sounds like a feasible solution. Or at least a true open source .org CA who could provide these services - please don't read this as the .gov.

    2. Re:Noooooooooooo! by mckyj57 · · Score: 1

      I agree. I also accelerated the switchover of
      my clients because of Verisign's spam.

      The following companies also have root-signing
      certificates in Navigator 4.7:

      ABAecom (Am. Bankers Assn)
      ANX Network
      AT&T
      Access America (DST)
      American Express
      BBN
      BelSign
      Canada Post Corp.
      DST (provider to quite a few others)
      E-Certify
      Entrust (DST)
      Equifax
      GTE CyberTrust
      GlobalSign
      IBM
      KEYWITNESS
      MCI Mall
      National Retail Federation (DST)
      Novell (DST)
      TC TrustCenter
      UPS
      United States Postal Service
      Uptime Group

      Anyone know whether any of these sell certs?

  5. Re:Buying your competition? by mindstrm · · Score: 2

    Why is this a problem? *ANYONE* can run a CA, it's a matter of how you get your CA recognized by current browser that I wonder about.

  6. Re:I should point out... by mindstrm · · Score: 2

    They are the only two who happen to be handing them out; many other CA's are preloaded in NS and IE.. they just aren't in the business.

  7. What about Equifax? by FatSean · · Score: 1

    Equifax is definately in the Certificate Provider business. Some rather large companies do business with them. Are they that much of a non-player?

    --
    Blar.
  8. The whole secure cert scene is a scam by Anonymous Coward · · Score: 0
    Looks like the "old boys club" w.r.t. secure certificates is now rapidly approaching a monopoly situation. Verisign are clearly the number 1 secure certificate vendor with Thawte Consulting a distant 2nd (but offering cheaper certificates). Both these vendors pay a large wad of cash to Netscape and Microsoft each year for the "privilege" of being listed as a trusted certificate authority (but who decides they are trusted ?!!).

    To make sure that Verisign loses no more secure certificate business to Thawte, they've bought them up for $575m ! So this means that Verisign can increase its market share and keep its high prices too. Bad news all round - this whole secure certificate thing is an absolute scam (over 250 quid to run a program that generates 15 lines of text ?), as is the TRIPLE cost of the 128-bit certificate vs. the 40-bit certificate (when the generator's probably identical except for a KEYSIZE=128 definition I bet !).

    Let's see:

    .co.uk domain cost to Nominet members: 5 quid + VAT a year
    Verisign secure cert for .co.uk domain: 259 quid + VAT a year
    [ Using prices on BT's Trustwise site at http://www.trustwise.com/ ]

    Anyone care to say "rip-off" ?! Verisign should be thoroughly ashamed of themselves, especially considering the secure certificate application process is virtually entirely automated (they only get involved if there's a problem) so they can't even justify the prices via admin costs. I've always said it's a cash cow and now it's a golden goose, a lottery jackpot-winning ticket, a scam, a monopoly and an outrage as well !

  9. Re:More closed source monopoly by mindstrm · · Score: 2

    You know, I felt good knowing there were 20 some other organization CAs preloaded in NS and IE....
    but now that Verisign ownes all but 4 or 5 of them, I wonder... this is sleazy!

    Really, though.. run your OWN ca, and direct people to a page that explains how the whole process works (more than Verisign does!) to the common man, and have them simply accept the key into their browser.

    Better yet, offer them client keys as well!

  10. Re:You can submit your comments to the DOJ by Y2K+is+bogus · · Score: 1

    http://www.usdoj.gov/atr/contact/newcase.htm

    That's the page where it says to send complaints to.

  11. Only 200 pounds? by / · · Score: 3

    Heck, I don't weigh that much less than that. Neither do a bunch of my friends. Maybe we should get together and beat up on Verisign and steal its lunch-money.

    These companies really have to learn that it's not that impressive if they weigh only slightly more than the average American male. Even if America is a chronically obese nation.

    Maybe Microsoft would like to help them out by hooking them up with some of that combination bovine-growth hormone and human-g rowth hormone regimen that's keeping Gates's hair so glossy and thighs so sexy. They'll help make Verisign a man. How do I know this? Try searching Google for "make you a man". Microsoft comes up as #2. Does Judge Jackson know about this?....

    --
    "If one is really a superior person, the fact is likely to leak out without too much assistance" -- John Andrew Holmes
  12. Verisign certs are worthless in about 10 days by thogard · · Score: 1

    At the end of the year, the Verisign certs will be about as useful as a self-signed one. The bad PR that could cause would give them no choice but to buy out Thatwe because if they get a bad write up in something like the Wall Street J about the problem, they effectly will have no market share, a huge debt and no way out. When that happens their stock goes into the penny stock class and the doors close.

  13. The one thing that really bugs me by mindstrm · · Score: 2

    Is...
    I understand PKI. I understand x.509 certificates.

    What I don't understand is why, in the first place, X.509 certificates were required to use SSL. It should not be necessary. Why are modern browsers set up so that you cannot use SSL unless you have appropriate x.509 certificates? I mean, I have no problem with the browser telling me it's unsigned, or untrusted, but I should still be able to use session encryption.
    Feh.

    1. Re:The one thing that really bugs me by Zigg · · Score: 2

      (I know you probably already know this, but others may not.)

      Certificates are required because you need to know that the other end of the connection is who they say they are. Without that assurance, you open yourself up to a man-in-the-middle attack:

      1. Alice is using SSL to talk to secure.bob.com. Eve wants to see what Alice and secure.bob.com are talking about.

      2. Eve positions herself between Alice and secure.bob.com. She creates two public/private key pairs. She sends one of those public keys to Alice, posing as secure.bob.com. and the other to secure.bob.com, posing as Alice.

      3. As Alice sends data to secure.bob.com, Eve decrypts it with her key and re-encrypts it with secure.bob.com's real public key. The same happens in the other direction.

      This can't happen with certificates because secure.bob.com's public key is authenticated with the certificate. (Admittedly, Alice doesn't have a cert in most SSL transactions, but most people settle for the end that they feel needs to be most trustworthy -- the server -- to have the cert.)

      Now keep in mind that most browsers are designed to keep the large portion of the Internet-using public (who are stupid) from hurting themselves. Hence the need for certificates, because there is no way you are going to get Grandma to understand man-in-the-middle attacks -- and if you tell her about them, she most certainly will not trust SSL in general.

      That said, the SSL patches to lynx don't require certs. :-)

    2. Re:The one thing that really bugs me by Elessar · · Score: 1

      Well if you wish you can set up an SSL server, create your keys; and then sign your own certificate, i.e. "Signed by John Doe Certificate Authority". The server will work perfectly well and the browsers can talk perfectly happily with it. The only problem is when you access the site you will get some dialog boxes popping up telling you that the site is untrusted. Modern browsers will let you set up an encrypted session with a server that they don't trust - but they will tell you what they're doing first.

  14. Maybe we should ask Judge Jackson by / · · Score: 2

    "Most harmful of all is the message that Verisign's buy-outs have conveyed to every company with the potential to innovate in the securities industry. Through its conduct toward Netscape, Thawte, Compaq, Microsoft, and others, Verisign has demonstrated that it will use its prodigious market power and immense finances to harm any firm that insists on pursuing initiatives that could intensify competition against one of Verisign's digital-certificates products. Verisign's past success in hurting such transactions and stifling innovation deters investment in technologies and orders that exhibit the potential to undermine Verisign. The ultimate result is that some innovations that would truly benefit customers never occur for the sole reason that they do not jive with Verisign's vision."

    With appologies to Brunchi ng Shuttlecocks.

    --
    "If one is really a superior person, the fact is likely to leak out without too much assistance" -- John Andrew Holmes
  15. Re:And this would mean...what? by roadoi · · Score: 1

    Obviously you are not a nerd as such. 95% of *NIX users i know, admins, graphic artists etc have installed apache+mod_ssl and required a cert. With verisigns rediculously high prices, and the vast majority of these people not wanting to pay this much, they shopped around and found thawte. This is all in the normal system install/configuration phase. No brain power required, just common sense.

    --
    In God We Trust, Everyone else must have an X.509 certificate.
  16. Entrust is a Provider of Enterprise PKI Systems by dave_aiello · · Score: 2
    Entrust's primary business is creating entire Private Key Infrastructure systems (PKIs) for Fortune 500 businesses. These are the systems that allow companies to issue and revoke their own certificates. Entrust has a big business in large corporations with thousands of employees.

    In certain circles in industry (like financial services), Verisign was primarily looked at as a service bureau who was willing to deal with small businesses. I realize that from the perspective of the consumer and small ISP they look like the only game in town. But, this was never the case at the high end.

    I think this is a good acquisition for Verisign. It solidifies their position in the small and mid-sized business marketplace. This also creates an opportunity for a competitor, although it may not be a small company that tries to enter this market.

    --

    Dave Aiello

    --
    -- Dave Aiello
  17. Re:How does international anti-trust work? by mindstrm · · Score: 2

    There is a simple out for this though.. browsers like MS and NS simply have to recognize OTHER CA's as authoritative. This is the only thing giving them power.

    (gee, is that somewhat similar to the current DNS structure that gave Verisign so much power? ie: it only works because our products all use it by default.)

  18. Other CAs for email besides Verisign by Zico · · Score: 2
    1. Re:Other CAs for email besides Verisign by badzilla · · Score: 1

      I visited the BankGate site and my browser reported that their root was untrusted and would I like to trust it? How should I know??!? I said "no thanks" so the transaction failed.

      I visited the GlobalSign site and my browser reported that their root was untrusted and would I like to trust it? How should I know??!? I said "no thanks" so the transaction failed.

      This is how it works in the real world with unskilled users, it's a major deployment problem (just ask anyone who has ever tried to implement self-signed certs in an intranet.) This is why only the companies with their roots in the browsers are going anywhere, at present this means Thawte and Verisign - period. I know I said Win2K or SP6 would change that but not for the foreseeable future...

      Oh yeah and I visited the BT TrustWise site and my browser reported that their root was ... well, Verisign's root actually! They are just a reseller.



      --
      "Don't belong. Never join. Think for yourself. Peace." V.Stone, Microsoft Corporation
  19. Action plan by Anonymous Coward · · Score: 0
    This merger would be really bad. How about:

    1) Trying to block the deal: solid lobbying of the US and South African government, petitions, etc., pressure of public opinion on the organization which is supposed to approve the deal (if any), alerting and starting up coordinated action with organizations, lawyers, specialized in anti-monopoly immediately.

    Let us do something - NOW... 2) Starting to get down seriously on the business of setting up an alternative, cheap "Open Source" signing authority. Furtune 500 companies don't mind to pay outrageous price for anything that their smaller competitors can't afford. But the overhelming majority of companies across the world is small business. Thawte's success was based on this customer base.

  20. Now I C by Anonymous Coward · · Score: 0

    The spelling error in the article... gotcha...

  21. And this means? by DaveBarr · · Score: 1

    please, if you take the trouble to post stuff like this, at least let us why we should care. --Dave

  22. Re:First Post by Anonymous Coward · · Score: 0

    Moron

  23. Bah! by Chip+Stillmore · · Score: 1

    Thawte ... Verisign ... certificates ... security ... all this talk is giving me a headache ... it's making me thirsty too ... I need another beer.

  24. too bad: they offered much cheaper certificates by Anonymous Coward · · Score: 0

    Verisign charges 4X as much for equivalent digital certificates. Better "synergy" is corporate speak for a monopoloy.

    1. Re:too bad: they offered much cheaper certificates by vawlk · · Score: 1

      hehe, I just renewed my cert as of the 15th.

    2. Re:too bad: they offered much cheaper certificates by storem · · Score: 1
      I fact you could have your own personal vertifcates for free! I believe there is the need for a non-profit CA on the Internet. Something like the PGP key database at MIT, but using X.509 certificates.

      Did it exist: yes, THAWTE! Does it still exist: with Verisign acting as the key God? I wouldn't be suprosed if I'd get a bill next week.

  25. Good move, Thawte, bad move, Verisign. by twit · · Score: 4

    First of all, good move, Thawte. They've successfully maximized shareholder value. In other words, they've sold out at the right time. Verisign, having grabbed a lot of the big names, will probably go on to increase its market share; Thawte, having failed to, may be at the peak of its value - especially when, not if, the net stock bubble collapses.

    Bad move, Verisign. First of all, the net stock bubble is called a bubble for a reason. However, when acquiring other companies, you should buy for value or make acquisitions strategically. Does Thawte own anything, other than marketshare, that Verisign doesn't already have? In most mergers and buyouts, the purchaser usually ends up losing equity when the euphoria wears off. I doubt that this will be an exception to the rule.

    I can deplore Microsoft's mania in acquisitions, but more often than not they acquire intelligently - taking out possible competitors, buying into new technologies. They don't acquire just for the hell of it. Paradoxically, they have too much money to do that.

    Bad move, for the global net. Thawte is a South African company, and so the purchase takes an international venture with global reach and sucks it into the gaping maw of Silicon Valley. Not that there's anything intrinsically wrong with the valley. It's just that something sticks in my craw with one location dominating an entire industry.

    Bad move, for everyone. A 200-lb gorilla in any industry is bad for business. A 200-lb gorilla in the security industry is worse. The security industry is based on trust (or at least mistrust) :-), and a 200-lb gorilla, with enough marketshare, can drive the market into inferiority and incompetence quite easily. Look at the consumer operating system market if you don't believe me :-).

    --

    --

    --
    There is no premature anti-fascism. -Ernest Hemingway
    1. Re:Good move, Thawte, bad move, Verisign. by Col.+Panic · · Score: 2
      It's just that something sticks in my craw with one location dominating an entire industry.

      Like the possibility of the entire industry's headquarters being eliminated in one really big earthquake like the one California may have in its future?

    2. Re:Good move, Thawte, bad move, Verisign. by dsplat · · Score: 1

      Perhaps. But there is also the possibility that this is the push that will be needed to get other players to jump into the market. There will certainly be markt niches that Verisign won't be filling. Other players can work on those. This round goes to Verisign, but the game isn't over.

      By the way, I don't have any personal axe to grind against Verisign. I like to see a competitive marketplace with some choices. When the only choice is whether to feed the big gorilla, or stroll over to the park and watch the ducks because there aren't any other primates left ....

      --
      The net will not be what we demand, but what we make it. Build it well.
    3. Re:Good move, Thawte, bad move, Verisign. by treat · · Score: 1

      But this is a market that's very difficult to enter. You have to get the vast majority of browsers to include your root certificate. That's why this is so bad. It means that people will *have* to deal with Verisign's ridiculous pricing if they want to set up an https server that's used by the public. Just at the point where Thawte was entrenched enough to be a completely viable alternative.

  26. Versign stock up 15% on monopoly acquisition news by Anonymous Coward · · Score: 0

    Time to buy stock of yet another computer monopoly: MSFT, CSCO, now VRSN.

  27. VRSN stock price performance by Anonymous Coward · · Score: 0
  28. Cornering the Market?! by mlesesky · · Score: 1

    Verisign makes a move that would leave it in a very strong position in the market. Now down to GTE, Belsign and Verisign - with Verisign having established itself as the Wall Street darling. It will continue to move higher as word spreads.

  29. This monopoly is due to US export controls by Anonymous Coward · · Score: 0

    Thank your legislators and congressmen for creating this wonderful monopoly!

  30. Holy fuck - Versign + Thwate == 99% of market! by Anonymous Coward · · Score: 0

    You could see from the above post that Verisign was clearly losing revenue from Thwate! Hello, US DOJ - please intervene for consumers!

  31. Microsoft owns a large chunk of Verisign by Anonymous Coward · · Score: 0

    As a shareholder of Microsoft, I can attest to the fact that Microsoft (about 2 years ago) purchased Verisign stock. It's sad ..

  32. How do browser certificates work? by johnburton · · Score: 1

    Do they work like PGP signing where if you trust can be sort of delegated down a "tree" of signed certificates? Or does wach and every certificate need to be provided by a ceritified authority?

    --
    Sig is taking a break!
  33. next chance for additional certificates: Mozilla! by smk · · Score: 1
    First of all I'm scared. A company ruling mor then 90% of the ceritifacte market is a nightmare. I'm glad I chosed PGP instead of S/MIME.

    But the question is: How to introduce new (root) certificate instances? Well, only a new browser version will make it possible for the "dummy" user without hassle.

    So next stop is Mozilla/Netscape 5.0.

    I suggest on this "stop" to add/introduce an open certificate instance(but don't read that as "insecure") like the german cert/dfn. This root instance should be driven by scientific or nonprofit institutes with can't be beaten or bought.

    --
    * Smile. People will wonder what you think. *
  34. Yes, that's probably going to be a problem. by Static · · Score: 1
    It was also my immediate thought when I read the news article.

    Wade.

  35. You can submit your comments to the DOJ by Y2K+is+bogus · · Score: 4

    Please moderate this up!

    You can submit your comments on this matter to:

    newcase.atr@usdoj.gov

    I have sent my comments and sent this email to my friends, do the same!

    1. Re:You can submit your comments to the DOJ by absnom · · Score: 1

      Perhaps the more appropriate place might be the South African government's Dept. of Trade and Industry (http://wwwdti.pwv.gov.za/dtiwww/). The Minister is Mr A. Erwin. His snail-mail address is:

      Private Bag X274
      Pretoria
      0001
      South Africa

      He also has an email addess listed on the web site, but spamming him might be counter-productive. Does anybody from South Africa have a better person/place to email/write to? They should really be alerted to how bad this merger is for all of us.

    2. Re:You can submit your comments to the DOJ by Sharkeys-Day · · Score: 1

      I would like to verify that this is the correct place to complain to before spamming anyone.

      Can you post information more information about this address, such as where it came from and how best to identify the issue we are protesting?

  36. You can't always talk to the local office. by winterstorm · · Score: 1
    Thawte also has "offices" in countries all over the world. However when you run into a snag (the local office can't verify your documents, or is taking weeks to verify them) they direct you to deal with their head office.

    I've dealt with Thawte for a long time. Most of the time you get great service from the local office (in my case the Toronto branch) but I've had to deal with their head office on three occasions in the last three years.

  37. I've never seen an issue that EVERYONE agrees on by Anonymous Coward · · Score: 0

    ...but this is such an issue - Verisign SUCKS. Just SAY NO to monopolies!

  38. Call the Justice Department by fumble · · Score: 1

    EVERYONE call this number and complain about the ridiculous monopoly that has ensued!

    The Justice Department, Anti-Trust Division
    (415)436-6660
    (San Francisco, California)

  39. Not so fast! by barzok · · Score: 1

    Remember, this deal is subject to approval still. Hopefully, someone in gov't will notice this one company will be 98% of the market and will put the brakes on the deal.

  40. Re:Bad news by LordStrange · · Score: 1
    It's especially bad news given that verisign's commitment to customer service seems to indicate that they already think they have a monopoly. IOW: They suck with more negative pressure than a telco.

    That assertion is based on some recent personal experiance.

    --

    License: By reading this you are agreeing that you agree with me.

  41. TOO MANY SECRETS!!! by Anonymous Coward · · Score: 0

    It's a conspiracy, man!

  42. Re:Anyone thought of Enrust.net? by Anonymous Coward · · Score: 0
    This now means that the Entrust.net intermediate cert is OWNED and could be YANKED by Versign. And Verisign could be the only major player.
    Oh calm down. What are they going to do, remove it from everyone's browser? The Thawte root CA is hardcoded into your (and my) browser. It's not going to disappear from existing browsers just because Verisign bought Thawte. What they could do is move all their customers to a Verisign cert and once that's done ask MS and Netscape to no longer put the Thawte root CA in newer versions of the browsers. Older browser versions would then still trust the Thawte root (and by extension Entrust.net's root), but the new ones would not. It seems to me that - given the obviousness of the situation - it's pretty likely that Entrust.net is going to have its own root CA in the major browsers by the time that that happens.

    I think Entrust.net is and will continue to be a viable alternative to Verisign. A good one, in fact.

  43. Export controls "don't" restrict authentication by billstewart · · Score: 1
    The US Export Controls, annoying as they are, sate that they don't restrict export of authentication products, only privacy-protection products. This means that a program that only signs and verifies keys, but doesn't generate them, is perfectly exportable, and a service that certifies keys can operate cross-border with no harassment.


    In reality, it's a bit more restrictive than that - the RSA algorithm uses the same routines for encryption and signature verification, and for decryption and signature, so export of source code for RSA-based certification systems, which should be legal, might not be (or at least might have trouble getting permits if you apply for them; John Gilmore's permit for DNSSEC was granted and then yanked). But export of binaries still should be fine, assuming they're only designed to do signatures and verifications well, and that's enough to run a business on.


    Digital Signature Algorithm/Standard (DSA/DSS) signatures only provide signing/verification, not encryption, so a system using them should be exportable without a permit, even in source code. (In reality, the "subliminal channel" misfeature means you can use it for slow symmetric-key encryption by hiding bits in your choice of random numbers, but that's ugly and the Feds like to pretend it's not built-in - at least if you don't add subliminal-channel support to your crypto source code.)

    --

    Bill Stewart
    New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
  44. Re:Offtopic, sue me, no wait mod me down by daviddennis · · Score: 2

    I believe that one was about a 7.x. Woke me up, shook me up a bit, but caused essentially no damage. The only injuries came from an Amtrak train that got unlucky.

    But even the Northridge earthquake, with an epicentre right in the middle of a heavily populated area, only killed 16-odd people. It was a smaller earthquake, but the really big ones are only expected to occur in the boonies. The effects of the 7.x in a distant area of Southern California were way less than the effects of a 6.x in a major population centre.

    D

    ----

  45. Re:First Post by Micah · · Score: 1

    How in the HECK did that comment get a score of 1??????

    Rob, I think we have a Slashdot bug here. An AC posted a first post message, and it got a score of 1!

  46. Re:Verisign Monopoly and price gouging - how? by Anonymous Coward · · Score: 0


    If what you want to do is admin your server over a secure webpage, you don't need their services at all. Just
    generate your own certificate and *presto* ... your own secure server connection.



    how exactly do you do that? Can you elaborate?

  47. I'm disappointed of Thawte by DarkToast · · Score: 1
    Indeed. Thawte's been the most friendly 'major company' I've seen yet.
    • The Web of Trust: instead of Verisign personal certificates, only costing money and making no assumptions about identity, unlike Thawte, which issues such certificates for free, following a Web of Trust scheme - never just to make money
    • Very friendly to the open source people, supports PGP and open source web servers, even back then when Verisign refused to know any non-commercial SSL implementation for Apache
    • They offer free IRC-based technical support
    • They link and suggest Fortify on their site
    • They have the best privacy policy I've ever seen - read it - you'll like it!
    Now, would Verisign sell Thawte certificates when Verisign's root CA expires at 1/1/2000 on Navigator 4.5 and lower? I wonder if this was their intention...
  48. Re:Goodie Goodie Gumdrops by vawlk · · Score: 1

    One other notable here. Verisign is going to have a lot of problems with their root rollover in a bunch of different browsers. Come Jan 1st, many browsers certs are going to expire. Thawte had this problem a couple fo years ago, but wasn't that big of a deal. But Verisign is looking at a large percentage of browsers that have to get "fixed" by installing a new cert. Thawte will not have this problem and they were hyping this BIGTIME on their site for the last month or so and it has mysteriously disappeared. Watch those prices...I got lucky and renewed as of the 15th.

  49. Why? by cybaea · · Score: 0

    Why on Earth did they do it? just to create a monopoly?

    --
    Hi!
  50. Last Post! by Last+Post! · · Score: 0

    This is great. It's nice to know that running some key generators is worth $575 million. That makes me feel swell, since I made less than a thousandth of that this year.

    Of course, I was only doing silly computational physics. Nothing as meritorious as running a key generator.


    _.......................__
    ||.....__...._._||_..||-\\..._...._._||_
    ||......_\\.(/_'..||....||-//.//.\\.(/_'..||
    ||__((_||_,_/).||_..||....\\_//.,_/).\\_
    The final word; anything following is redundant.

    1. Re:Last Post! by HP+LoveJet · · Score: 1
      Oh, come now. It's not just running some key generators; it's also paying for the care and feeding of lawyers to draw up CSPs and contracts that say things like:


      In the event that anything goes wrong, or you use your certificate for some nefarious purpose, you indemnify us of any wrongdoing. We disclaim everything.


      spawn_of_yog_sothoth

      --
      spawn_of_yog_sothoth
  51. P.S> leaf it at zero by Anonymous Coward · · Score: 0

    save the points for the good comments :-)

  52. Re:1st (sorry) by Anonymous Coward · · Score: 0

    sorry, i would erase that if i could.

  53. Goodie Goodie Gumdrops by Necroleptic · · Score: 1

    Although internet security is a high priority on everyone's list, but this deal does not seem to extend that, as it says in the article is just a purchase transaction, not like some M$ assimilation practices.

    1. Re:Goodie Goodie Gumdrops by Anonymous Coward · · Score: 0

      No. This is bad. Thawte is really the only viable alternative to verisign, because only thawte and verisign have root certificates installed in web browsers. If the deal is allowed to go through verisign will be able to charge much more for their certificates. This is very microsoft style. Verisign certificates are already much higher in price than thawte certificates - particularly for object (code) signing. I hope it gets squashed.

  54. Twat bought by Vagisign by FatSean · · Score: 1

    There's something fishy about this deal...

    --
    Blar.
  55. Buying your competition? by Anonymous Coward · · Score: 0


    Hopefully this will not be allowed, like the
    Adaptec - Symbios deal. This is a serious
    anti-trust & anti-consumer merger.

    Mark

    (maybe my 1st f1rs7 p0st??)

  56. ... by mistalinux · · Score: 1

    I've come to the conclusion long ago that everything companies do can be attributed to what the decision makers believe will make them more money. Think about that.

    --
    Sosumi. just kidding. DONT!
  57. wonderful by CodeMonky · · Score: 1

    Well this kinda sucks seeing as how i have to renew our certificates (from thawte) shortly. (1/2000)
    *SIGH*

    --
    --"Karma is justice without the satisfaction"
  58. 1st by Anonymous Coward · · Score: 0

    great

  59. $575 million?? by Raymond+Luxury+Yacht · · Score: 0

    That's one spicey meat-a-ball!

    To Thawte or not to Thatwe, that is the question....


    --

    Ceci n'est pas une sig.
  60. This is terrible! by winterstorm · · Score: 3
    Thawte services are very different in flavour than Verisigns. Thawte has a "web of trust" system for personal certificates based on the PGP web of trust ideal. Thawte offers wildcard certificates. Thawte certificates are priced reasonably.

    Thawte provided signing support for SSLeay keys very early on. Verisign is slow to change.

    On the other hand if things get complicated (if your verification documents for a certificate are not "normal") then dealing with Thawte can be a pain. Thawte has its head office in Africa. Have you ever tried to send a long fax to Africa? If you get a clean line you might get one or two pages through at a time.

    1. Re:This is terrible! by austad · · Score: 1
      Have you ever tried to send a long fax to Africa? If you get a clean line you might get one or two pages through at a time.

      Thawte has offices in the US, dealing with them is easy.

      --
      Need Free Juniper/NetScreen Support? JuniperForum
    2. Re:This is terrible! by philzaw · · Score: 2
      Agreed :(

      Please read Thawte's President essay.

      Especially comments on VeriSign:

      A loss of $21 million, on revenues of $9 million, of which $3 million in revenues came from a book transaction with a parent company. Damn. Wow. Sheesh.
      or
      Will we list Thawte? Unlikely. I don't think investors would understand and be prepared to pay a premium for a small company that is profitable but not over hyped. And I like my autonomy too much! Besides, we plan to diversify and push the "Thawte" brand independently of certificates, so it will be nice to have a wholly owned cash generator over time. But that's a different story, and actions speak louder than words!

      It might relate only to IPO, but...

  61. I should point out... by squarooticus · · Score: 1

    ...that Verisign now has a monopoly on commerical browser certificates. Thawte and Verisign are the only two companies to issue commercial browser certificates for both NS and IE.
    --
    Kyle R. Rose, MIT LCS

    --
    [ home ]
  62. Re:who these people by Anonymous Coward · · Score: 0

    aTest

  63. Good grief, who's left? by Count+Fragula · · Score: 3

    Looking at the list of the 27 root certifications in IE 5, i see that 21 of them are either held by Thawte or Verisign. Now, I've been a Verisign customer for a long time, and I like the fact that I can count on their root certificate being in 99% of browsers out there, but there was always a peace of mind that came with knowing I had Thawte to go to if i was ever dissatisfied. Well, no more.

    Yikes.

  64. Verisign Monopoly and price gouging by protektor · · Score: 2

    Anyone notice that you can't just buy a server certificate anymore from Verisign. They want to sell you a whole package deal of services and other things for 128 bit certificates.

    http://www.verisign.com/server/prd/g/index.html

    I also don't like the fact there is now no competition to Verisign and that they have huge requirements and slow to respond to problems and can't track documents within their own company that you send them. If you can't do everything the Verisign way then God help you since they will drag everything out forever and loose documentation you send them.
    I also see they are buying Signio E-Commerce payment service for busines to business e-commerce transactions. Where will they stop, they are starting to sound like they want to be like Microsoft only they want to control all secure and E-Commerce stuff on the internet.
    Verisign also charges more or at least use to charge more for basic secure certificates. Looks like the days og just buying a certificate for your server are over. Now you have to buy a whole package of services and you probably won't be able to get wildcat certificates any more either. Which is a real problem since I shouldn't have to pay $950*x just for a few servers in my own domain for easier adminstration purposes to do internal stuff via a secure web page.

    This just plain sucks!

    1. Re:Verisign Monopoly and price gouging by um...+Lucas · · Score: 2

      Verisign also charges more or at least use to charge more for basic secure certificates. Looks like the days og just buying a certificate for your server are over. Now you have to buy a whole package of services and you probably won't be able to get wildcat certificates any more either. Which is a real problem since I shouldn't have to pay $950*x just for a few servers in my own domain for easier adminstration purposes to do internal stuff via a secure web page.

      If what you want to do is admin your server over a secure webpage, you don't need their services at all. Just generate your own certificate and *presto* ... your own secure server connection.

      ---------

      If the price on their certificates goes up, that'll be bad... but really you only need to purchase a certificate if you're setting up an ecommerce site. If that's what your doing, then $500-$1000 is a drop in the bucket. If that's not what you're doing, you can probably just sign your own.

  65. First Post by Anonymous Coward · · Score: 1

    Hahahahahahahah

  66. time for an open-source competitor by epictetus · · Score: 5

    Verisign is sure to jack up their prices if and when the deal goes through. There should be a market for cheap certificates sold to small sites that want to be secure without paying a Verisign tax.

    There's already open-source software out there for generating certificates. The other barriers to entry are:

    1. Name recognition. If you're in charge of security at a medium to big size company, your chief goal is to protect your own ass. To that end, you'll spend the extra money to buy Verisign, because nobody ever got fired for using Verisign.

    2. Being in the browser. This is a big one; your CA cert has to be pre-loaded into your user's browsers. This involves paying many thousands of dollars to MS and Netscape.

    The other things you need to be a CA are:

    1. Legal staff and Certification Practice Statement.

    2. Clerks for researching and verifying identity.

    3. A killer operations and security infrastructure to protect the CA's key and prevent unauthorized signing.

    CAs can and should be a commodity. The thing to watch out for is Verisign introducing proprietary technology into their certificates, or making exclusive deals with the browser manufacturers.

    1. Re:time for an open-source competitor by freddie · · Score: 1

      Somebody should organize something like this. With Netscape 5 coming up, I think that'd be a good chance to bring up a new CA. By the way, you might also get away with paying money to the much more agreeable redhat and debian instead for them to include your certicates. --fred

  67. MODERATE THIS UP TO A 5 PLEASE by Anonymous Coward · · Score: 0

    VERY INFORMATIVE

  68. Monopoly!! Monopoly!! by Anonymous Coward · · Score: 0

    This is yet another monopoly. I don't understand why Verisign would want to do this. On the other hand maybe it'll help other less established competitors, because so many people might be drawn away by the fact that verisign has so much full control of all this stuff.

  69. HEE by Anonymous Coward · · Score: 0

    HOO

  70. Entrust offers 128 global too... kinda by griffjon · · Score: 1

    Entrust has global export approval for their website certificates, great customer support (speaking from experience), no Y2K expiration issues, unlike Verisign.

    There's only one catch.

    Their certs are signed off on by (drumroll) Thawte! Which is now a subsidiary of Entrust's rival, Verisign. Hm.

    --
    Returned Peace Corps IT Volunteer
  71. Anyone thought of Enrust.net? by Neter · · Score: 2

    Entrust.net is another certificate provider on the net. They are trying to go head to head with Verisign in the web server market. (They own the enterprise in Canada, and are one of two in the US Gov't PKI architecture)

    They did not want to pay the gazillions that it cost to have their CA cert embedded in the browsers, so they got THAWTE to cross cert with them.

    This now means that the Entrust.net intermediate cert is OWNED and could be YANKED by Versign. And Verisign could be the only major player.

    If this does not happen, then at least we will still have more than ONE choice for server certs.

    Just my $0.04 Euro.

    1. Re:Anyone thought of Enrust.net? by Neter · · Score: 1

      Older browser versions would then still trust the Thawte root (and by extension Entrust.net's root), but the new ones would not.

      This is true. I think the point that you are missing is that you have to dowload the intermediate cert to your server to enable the chain of trust to be completed.

      Verisign could remove this intermediate cert (as it is now theirs.) and thus one could not complete the installation of an Entrust.net issued cert into their servers.

      I agree entirely that older browswers will still trust the Thawte root. Verisign cannot take this away. But at the rate that things are changed in the browser market, newer versions are being released almost every couple of months. It will only take two months for people to stop trusting the Thawte root.

  72. FIRST!!1!1!!!! by Rev.+DOG. · · Score: 0

    PSTO1!!1!!!!1!!1!!

    --
    "Music is music, but anarchy is stupid." -- Eli Armen-Van Horn
  73. Damn! Thawte had clue by Anonymous Coward · · Score: 0

    Having worked with both, I find this news very disturbing. It was a pleasure working with Thawte, they really understood what they were doing. Verisign, on the other hand, are a bunch of idiots. (I mean, who in his right mind would make root certs expire at the stroke of Y2K?)

  74. Yeah but competition is coming, big time by badzilla · · Score: 1

    There are good reasons why Thawte or Verisign can charge more money for a certificate than you can charge. Firstly and most importantly their root certificates are shipped in both major browsers' trusted root stores. Secondly these companies can justifiably claim to be secure to the max.

    I believe having their root certificate in the browser is _the_ number one factor and this is due to change very soon - Windows 2000 and NT4 SP6 both introduce a large number of new trusted players into IE, for example Baltimore, Belgacom, Cable and Wireless, Deutsche telekom, Swisskey, etc.

    So maybe Thawte are grabbing the cash and getting out at what they think might be the top of the market... I've always considered Thawte to be a pretty smart company.

    And there really is a need for a Slashdot CA, people do not want to pay $200 to get a code-signing certificate just for some .jar file they are distributing for free anyway.

    --
    "Don't belong. Never join. Think for yourself. Peace." V.Stone, Microsoft Corporation
  75. the DOJ has its next assignment by Anonymous Coward · · Score: 0

    This news really upset me. I can't stand VeriSign, and will use anybody else in the world. I consider them worse than Micro~1.

  76. Re:More closed source monopoly by Zigg · · Score: 2

    Nice thought, but there are two central problems:

    1. AlterNIC tried this with DNS, and all it required was the cooperation of folks who ran DNS servers all over the world (a relatively small group, actually.) Didn't work.

      I definitely won't take the odds on anyone being able to convince the Internet-using public (most of which is stupid, frankly) to install new certs in their browsers. Also, forget about getting them preinstalled in the browsers -- M$ is buddy-buddy with Verisign, and without IE support, no one will use our CA.

    2. If sites are all directing folks to download new certs (I know this will happen anyway with the root rollovers, but bear with me), we will be training folks to accept any cert that they stumble across. Since anyone can create a cert, this could open up unsuspecting users to thinking a connection is ``secure'' when there is no guarantee (even the slight guarantee given by the current CAs) that the other end is who they say they are.

    I would say, at best, that if this goes through, SSL should be considered proprietary and dead, and should be shunned by those of us who think computing should be open. It's quite a shame.

  77. 30%? Mozilla'd give his left nut for 30%. by Zico · · Score: 1

    Internet Explorer now has over 80% of the browser market, and its lead is increasing each week.

    About Thawte, it's pretty coincidental for me to be seeing this article now, since I just signed up for a Thawte certificate late last night. There was one part of the sign-up process that was very unclear -- choosing a CSP. Thawte's web site did nothing for helping a new user decide the pros and cons of the different choices. I just went ahead and picked the Microsoft Base Cryptography because it was the default and because I know I can change it later, but could anyone recommend some links to comparisons between the different choices?

    Thankful cheers,
    ZicoKnows@hotmail.com

  78. Offtopic, sue me, no wait mod me down by toast0 · · Score: 1

    If you're going to have a big earthquake, i'd have to say california would be the best place to have it....

    not too long after the earthquakes in turkey, and taiwan, there was one in southern california larger than the one in turkey, but less than the one in taiwan (forgive me for being vague i don't remember the numbers) and if i recall correctly there were fewer than 10 reported injuries...

    then again it was in the boonies area of southern california, but thats where they seem to happen most lately anyhow

  79. Ouch... Thawte sold their soul to the devil by jCaT · · Score: 1

    I know someone that worked for verisign for a brief period of time, and they said that the company didn't have their act together *at all*. It sounded like most of the internal projects going on were horribly mis-managed, and that network security was an absolute joke. Apparently they use a lot of firewalls there, but there are so many holes punched in them that it defeats the purpose.

    Anywho, all I know is that verisign is twice as expensive and takes twice as long as thawte to get ANYTHING done. This is a prime example of the word "monopoly"... nowhere else does the consumer get screwed and not know any better.

  80. Re:Alternative certificate by toast0 · · Score: 1

    ummmm
    since when do prices go down due to increased demand?

    prices go up do to increased demand

    and demand increases due to dropped prices

  81. Question by Anonymous Coward · · Score: 0

    Does this have any impact on issuing certs for 128-bit servers outside the US? If you can only sell a 40-bit server abroad, sureley there's no need for 128-bit certs (as we all know, only the good old U of SA knows crypto stuff).

  82. MODERATE UP by Anonymous Coward · · Score: 0

    For those about to rock - we salute you!

  83. That's almost what Thawte was, and what PGP is! by billstewart · · Score: 1
    Not strictly open-source, since what they provide are certificates, not code that has a source to open, but what they provided is an alternate set of policies and prices for certificate service. Anybody else could do the same - they basically di d a good sales job as a second-source certifier, and appealed to the small market by lower prices and more flexible policies, and got the big browsers to include them.


    PGP doesn't do a hierarchical certification; it does a web of trust instead, where everybody can certify anybody else's key. The browsers don't use it, but the obvious way to adapt it would be to let you include your own PGP key as a certifier and trust anybody who's key you've signed.

    --

    Bill Stewart
    New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
  84. Go for the FTC also! by nealmcb · · Score: 1
    You can also submit them to the FTC:

    antitrust@ftc.gov

    This one is important - make your opinion known!

    --

    --Neal
    Go IETF!

  85. Who's up for a new CA? by JohnDonagher · · Score: 1


    I wonder how much it would take to start a low-cost, open certificate authority.

    No $300 cert charges, no renewal bullshit, just fax us acceptable information and we sign your CSR.

    I know one thing for sure - I don't relish the idea of dealing with Verisign (one word - ripoff). I've found Thawte to be a decent business (with the exception of them billing credit cards from South Africa - that doens't go over too well).

    I wonder if there's enough support among the open-source community to get something like this going?

    John

  86. Re:hello monopoly (OpenCA) by Thanatopsis · · Score: 1

    Actually "tens of millions" of dollars worth of corporate liability insurance doens't cost that much. My company has 5 million in liability, $5 million in errors and ommissions etc. It's relatively affordable and I can purchase additional coverage in blocks of 5 mil. The cost on insurance like that is about $2100 a quarter and it covers the same sorts of issues (we are software developers.) The barrier to entry is getting you cert bundled with browsers and you can bet I am looking into getting into the Cert business right now. It's a great opportunity.

  87. Darn! by stimuli · · Score: 1

    For those who haven't used it, Thawte is an alternative service to Verisign, whose rates are on average about one half of Verisign's. I think all of these Certificate services are overpriced scams, but at least Thawte was less so.

  88. And this would mean...what? by Anonymous Coward · · Score: 0

    Never heard of these folks. I'm too lazy to go find out who they are or why I should care. 'twould be nice to have a little sentence on the article explaining who these guys are, what they do, a link to their site, perhaps? Better yet, tell us why we should be interested in this acquisition. News for Nerds...not Cryptic References for Nerds, right?

    1. Re:And this would mean...what? by CodeMonky · · Score: 2

      These two companies are THE companies for digital certificates. If you ever needed to setup a secure web server or get a thrid party certificate these two were the people to see. Personally I prefer thwate because they were reasonably priced but now i have no choice. answer your questions?!

      --codemonky
      --http://www.stetson.edu/~paland

      --
      --"Karma is justice without the satisfaction"
  89. More closed source monopoly by cybaea · · Score: 2

    Frpom the Verisign press release:

    As a combined entity, VeriSign and Thawte will be able to implement a consistent set of global standards for the issuance and management of digital certificates for websites and software developers

    It sounds like they want to own the standards and establish a monopoly of closed source rules.

    And it will be a monopoly:

    They are also the only two digital certificate providers with commercial availability of 128-bit website certificates

    Any chance that the mergers and monopolies comission (or whatever it is called in SA) will block this? Please!? Not another MSFT.

    --
    Hi!
  90. This is _not_ good. by rise · · Score: 1

    The certificate business was already incestuous enough. This deal is basically going to leave the whole shebang in the hands of VeriSign and MS, and that can't be good for the rest of us. A system based on trust cannot rely on a small group of organizations known to play fast and loose with the public interest.

    1. Re:This is _not_ good. by Gurlia · · Score: 1

      Forgive my ignorance, but why must trusted certificates be handled exclusively by a bunch of companies??!?!? I think the way IE and NS comes with "trusted" certs is a little off... Doesn't it only represent certificates that NS and MS "trusts"? If the web of trust is entrusted (pun intended) upon a few companies, they're basically telling you who to trust -- or more bluntly, who they want you to trust.

      Isn't the whole idea of the web of trust mechanism to allow anyone to verify certificates they receive from somebody? Now if this verification goes through a bunch of companies (which eventually merge into a monopoly), isn't there the possibility that there could be some foul play?

      Competition is healthy. As long as certificate providers have competition, they cannot afford to play foul. But as soon as competition is gone, all bets are off. Mergers of companies like these that are the sole provider of certificates to IE and NS are not good.

      --
      mikre he sophia he tou Mikrosophou.
  91. hello monopoly by snorks · · Score: 1

    This sucks. Verisign sucks. What's the status on trusted CA's in Mozilla? It would be cool to make OpenCA the default and require all of that extra clickthru for Verisigns crappy certs.

  92. This is bad for us.. by Billy+Donahue · · Score: 4

    I've always thought that Thawte did
    a better job than Verisign. They are cheaper
    too, I believe..(though it's been a while)..

    They do NOTHING for you! They don't even
    make your site more secure...
    They are snake-oil salesmen, at best.

    Watch as Bruce Schneier gives these jerks a firm talking-to: here

    --
    -- The Funk, The Whole Funk, And Nothing But The Funk
  93. couple of problems... by mr_spatula · · Score: 1

    Aside from just being a monopoly here.... I was always reassured by the fact that Thawte Consulting was a SEPERATE ENTITY from Verisign. Going through them actually seemed to give some semblance of higher security. Then again, who knows what the future holds...

  94. Bad news by EisPick · · Score: 5

    Consider the following:

    • As this chart on the Thawte site makes clear, these two companies combined own almost 100% of the market.
    • The barriers to entry in this market are huge: A new certificate authority would not be recognized by the current installed base of browsers.
    • Having two competing firms in this market clearly benefitted consumers. A server certificate from VeriSign costs $349; Thawte's costs $125.

    This is bad news for consumers.

  95. I have a Thawte cert and this disturbs me greatly by Omnifarious · · Score: 3

    I got a Thawte certificate because their website promised that if laws ever changed in the country their database was in such that they had to divulge its contents, they were prepared to move their database within hours. I also got it because of their support for PGP public key signing.

    Now, they're being bought out by Verisign who I have no such trust in, and who isn't, IMHO, a good member of the community. I'm not at all happy about this.

    I think I'm going to ask the my Thawte certificate be revoked, and all my data wiped from their databases. I do NOT trust Verisign at all. They seem more like opportunists out to make a buck than people who really understand the paranoid world of security.

  96. Alternative certificate by Anonymous Coward · · Score: 1

    GTE (www.cybertrust.com) has a root certificate which is valid until 2018 in NS 4.5+ and MSIE 4+. It's a tad expensive, but let's hope their prices will go down due to increased demand.

  97. Re:hello monopoly (OpenCA) by Anonymous Coward · · Score: 0

    There's no way to do an open CA due to the liability concerns. Unless you're will to cover the several ten of millions of dollars in corporate insurance that would be required for an open ca with root certificates installed in the common web browsers. Not to mention the fact that MS would never allow anything open into any of their systems. So, you'd only be able to support CrapZilla (if it ever becomes usable). Good Luck getting people to buy a certificate that's only trusted by 30% of the web browsers that visit their web site.

  98. Worth the money or not? by Anonymous Coward · · Score: 1
    There's a little more to it than that. You have to keep those key generators awful damn secure. For any more than a base-level certificate you have to check that the recipient really is who he says. Plus you need the market position so everyone knows your public key.

    Of course as Bruce Schneier points out, PKI ain't such a secure and necessary deal as it's made out to be, so to a certain extent Verisign is just smoke and mirrors.

  99. How does international anti-trust work? by MattMann · · Score: 2

    If these were both American companies, I would think that this would run into anti-trust trouble, especially in the current regulatory climate. However, given that this is an international deal, does anybody know how regulation works?

  100. Thawte has a human face by linuchristo · · Score: 1

    a year ago, I browsed verisign and thawte's web sites to educate myself on certs. Verisign's web site was full of legal disclaimers, uninformative in the grand old bureaucratic style, and without humor or humanity. Thawte's web site was informative --a geek can learn things from it-- and had a human voice.
    what gubmint agency do I write to protest this merger?

  101. oh... "thawte" by bunnyman · · Score: 1
    Thawte Bought by Verisign

    Imagine my surprise when I read that Verisign bought Thought. I could understand if they had patented it, but bought Thought?

    I'm still wrong though.