Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Google dumps Symantec SSL certificates in Chrome, Android
© iTnews ^ | Dec 14 2015 6:51AM (AUS) | Juha Saarinen

Posted on 12/13/2015 7:34:57 PM PST by Utilizer

No longer trusted.

Google's products will no longer trust Symantec's digital certificates used to secure internet data communications, the company said.

Starting 2 December Australian time, Symantec's Class 3 Public Primary Certificate Authority (CA) root certifcate is no longer trusted by Google in its Chrome web browser, Android mobile operating system and other products.

Google software engineer Ryan Sleevi explained (https://googleonlinesecurity.blogspot.co.nz/2015/12/proactive-measures-in-digital.html) over the weekend Symantec intended to use the root certificate for reasons other than creating publicly trusted credentials. The certificate also no longer complies with the industry Certificate Authority/Browser Forum baseline requirements for best practice, Symantec said.

As a result of the above, Sleevi said "Google is no longer able to ensure that the root certificate, or certificates issued from this root certificate, will not be used to intercept, distrupt, or impersonate the secure communications of Google's products or users".

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: certificate; security; ssl; thegoog; windowspinglist
Android, The Goog, and Symantic -what a combo!
1 posted on 12/13/2015 7:34:57 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: dayglored

(((.)))


2 posted on 12/13/2015 7:37:57 PM PST by Squawk 8888 (I don't run; if you see me running, you should run too.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Dinosaur fight.


3 posted on 12/13/2015 7:59:34 PM PST by Talisker (One who commands, must obey.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Would you pretend like you’re explaining this to your grandfather?
Thanks.


4 posted on 12/13/2015 8:10:12 PM PST by kinsman redeemer (The real enemy seeks to devour what is good.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Talisker

I was thinking those cheesy Japanese monster movies where the gigantic monsters would go at one another and the audience didn’t GAS which one won ;’}


5 posted on 12/13/2015 8:20:38 PM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 3 | View Replies]

To: kinsman redeemer

To set up a “secure” internet connection such as one necessary for secure banking transactions, digital ‘certificates’ are provided by companies to keep others from falsely claiming to provide what they are not able to deliver.

For instance, you wish to purchase something from a company (Sears, Lowe’s, Colt Armaments, etc.) online so that company provides a digital certificate to ensure that you are truly dealing with them and not some fraud.

The article states that Google no longer trusts the Symantec digital certificates for certain reasons, which is notable since Symantec is a “security” company themselves.

The rest of the article gives more details.


6 posted on 12/13/2015 8:21:37 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

Okay... so is the risk to a customer doing business with Symantec (e.g. renewing a Symantec 360 license) or is the risk to users of Symantec when they are buying something from Sears, e.g.?

Or is it limited to Symantec customers who use Google buying services (e.g Google wallet)?

Thanks for your patience.


7 posted on 12/13/2015 8:27:06 PM PST by kinsman redeemer (The real enemy seeks to devour what is good.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Utilizer

“Google software engineer Ryan Sleevi explained over the weekend Symantec intended to use the root certificate for reasons other than creating publicly trusted credentials.”

Very interesting...


8 posted on 12/13/2015 8:28:11 PM PST by Wilhelm Tell (True or False? This is not a tag line.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Wilhelm Tell

I haven’t trusted Symantec ever since their help desk moved to (some other country.)


9 posted on 12/13/2015 8:31:53 PM PST by kinsman redeemer (The real enemy seeks to devour what is good.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Utilizer
Let's Encrypt is a new Certificate Authority: It's free, automated, and open.

What's up with this?

10 posted on 12/13/2015 8:34:51 PM PST by Stentor (RIP -- Nicholas Thalasinos.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Squawk 8888; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Google disses Symantec's old SSL certs ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Squawk 8888 for the ping!!

11 posted on 12/13/2015 8:40:46 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: kinsman redeemer

No worries. The risk is for a customer doing business with Symantec for any of their products.

The “Sears” reference was merely to place into perspective the importance of the Security Certificate. As far as I know, Sears Corp does not rely upon a Symantec Corp (a malware and virusware -etc.) cert for any of its offerings.

Unless SearsCo has a software sales division that offers Symantic products. Like OfficeMax or Staples would -but I am not that familiar with the Sears Product Lineups so I suppose it is technically possible.


12 posted on 12/13/2015 9:02:09 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 7 | View Replies]

To: kinsman redeemer

I suppose it is related to “Google Wallet” as well since they determine who is a trustworthy vendor and who is not, but I have never used their services so I can offer no assurances in that regard.


13 posted on 12/13/2015 9:04:22 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer

Ahh Symantic the company that kept buying other companies software and making the software unusable. Haven’t had any dealings with them since early 90’s. Crapware company.


14 posted on 12/13/2015 10:44:20 PM PST by free_life (If you ask Jesus to forgive you and to save you, He will.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Symantec still owes me $20 on a rebate they cheated me out of.


15 posted on 12/14/2015 2:56:12 AM PST by Fresh Wind (Falcon 105)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson