Jump to content

Still fuming over HTTPS mishap, Google gives Symantec an offer it can’t refuse

Samfisher

Source : http://arstechnica.com/security/2015/10/still-fuming-over-https-mishap-google-gives-symantec-an-offer-it-cant-refuse/

 

 

iMMm2Jb6.png

 

 

 

Google has given Symantec an offer it can't refuse: give a thorough accounting of its ailing certificate authority process or risk having by many measurements the world's most popular browser—Chrome—issue scary warnings when end users visit HTTPS-protected websites that use Symantec credentials. The ultimatum, made in a blog post published Wednesday afternoon, came five weeks after Symantec fired an undisclosed number of employees caught issuing unauthorized transport layer security certificates. The misissued certificates made it possible for the holders to impersonate HTTPS-protected Google webpages.

 

 

 

Symantec first said it improperly issued 23 test certificates for domains owned by Google, browser maker Opera, and three other unidentified organizations without the domain owners' knowledge. A few weeks later, after Google disputed the low number, Symantec revised that figure upward, saying it found an additional 164 certificates for 76 domains and 2,458 certificates for domains that had never been registered. The misissued certificates represented a critical threat to virtually the entire Internet population because they made it possible to cryptographically impersonate the affected sites and monitor communications sent to and from the legitimate servers.

 

Holy crap that's a big ass hole Symantec is in now.  Unauthorized HTTPS certs to Google domains, and over 2.5k total certs issued by now former employees.  Good on Google to put this out publicly, and to force Symantec to do something on their part or risk having users' Chrome browsers to spew HTTPS errors and warnings for ALL newly-issued HTTPS certs by Symantec.

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

Can Symantec die? Please?

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Can Symantec die? Please

They still do a pretty good job of security analysis, just like Kaspersky.  Their AV might suck but their other businesses are pretty good.

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

They still do a pretty good job of security analysis, just like Kaspersky.  Their AV might suck but their other businesses are pretty good.

Their Av business is downright wrong and borderline a scam. Have you bought a consumer PC lately? 

Their shit is reloaded with a  free trial and you have to use a removal tool to get rid of it. Which leads regulars uses to believe that they need to renew it or deal with it's popups. 

Been their tactic for years

Fuck them. They can die out. 

Lenovo too. 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Their Av business is downright wrong and borderline a scam. Have you bought a consumer PC lately? 

Their shit is reloaded with a  free trial and you have to use a removal tool to get rid of it. Which leads regulars uses to believe that they need to renew it or deal with it's popups. 

Fuck them. They can die out. 

Lenovo too. 

I know they do.  That's why I specifically said their AV business is crap, everything else they do is decent.

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

Norton, which is made by Symantec, is shit, so by extension, Symantec is shit.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

Even if Symantec is being a fucking asshat, why didn't google validate it's certs with ICANN.

Link to comment
Share on other sites

Link to post
Share on other sites

I know they do.  That's why I specifically said their AV business is crap, everything else they do is decent.

 

Norton, which is made by Symantec, is shit, so by extension, Symantec is shit.

If I shoot a kid in the face once a week, but I also do a bunch of amazing things for millions of people, I'm still terrible person. I still shoot kids in the face. 

Symantec still pushes Norton.

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Also, to any one saying their AV is bad; it isn't. its the way they market it.

 

https://www.av-test.org/en/antivirus/home-windows/windows-7/august-2015/norton-norton-security-2015-153228/

no shit 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

If I do a bunch of amazing things for millions of people but I also shoot a kid in the face once a week, I'm terrible person. I still shoot kids in the face. 

Symantec still pushes Norton.

They pushed Nortan on both of the discs for my Asus H87M Pro and Z97 Sabertooth MKII, they pushed it on my old laptop from 2003, they pushed it on my newer laptop from 2009. And I've yet to see an instance where their AV hasn't been a bloated POS that keeps on missing things.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

no shit 

Yeah.

 

Symantec is a shit company, but my response to the OP:

 

Why didn't Google Authenticate their certs with ICANN.

Link to comment
Share on other sites

Link to post
Share on other sites

They pushed Nortan on both of the discs for my Asus H87M Pro and Z97 Sabertooth MKII, they pushed it on my old laptop from 2003, they pushed it on my newer laptop from 2009. And I've yet to see an instance where their AV hasn't been a bloated POS that keeps on missing things.

Every AV in existence, past and future, will miss things. 

 

 

 

Yeah.

 

Symantec is a shit company, but my response to the OP:

 

Why didn't Google Authenticate their certs with ICANN.

 

I believe very few companies actually have the authority to issue certs, and those certs are universally trusted cos the companies that have the authority are generally trusted.  Who knows :P

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

Ehh at least their AV does something

 

Also, to any one saying their AV is bad; it isn't. its the way they market it.

 

https://www.av-test.org/en/antivirus/home-windows/windows-7/august-2015/norton-norton-security-2015-153228/

Free Norton 360 from Comcast for me...so basically 2 scumbag companies that other people think but i'm fine with.

Link to comment
Share on other sites

Link to post
Share on other sites

Norton and Kaspersky both did the same thing once upon a time to my x58 and x79 builds--the anti-virus screwed, attacked itself after an update, and then somehow corrupted and killed the USB drivers, video drivers, and sound drivers.  

Oddly enough that has happened to a few people I know as well.  Might be Florida luck, but ESET and F-Secure never fail me.

Make them squirm - Google overlords.  Make. Them. Squirm.

Link to comment
Share on other sites

Link to post
Share on other sites

Every AV in existence, past and future, will miss things. 

 

 

 

 

I believe very few companies actually have the authority to issue certs, and those certs are universally trusted cos the companies that have the authority are generally trusted.  Who knows :P

I've had free Antivirus pick up what Norton missed.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

I've had free Antivirus pick up what Norton missed.

 

And it would miss something else that Norton will not, there's 0 AV in the world that can catch everything.

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

Can Symantec die? Please?

 

They also do security analysis

 

and they're pretty good at it

 

Their AV can just go die in a hole*

Link to comment
Share on other sites

Link to post
Share on other sites

Their Av business is downright wrong and borderline a scam. Have you bought a consumer PC lately? 

Their shit is reloaded with a  free trial and you have to use a removal tool to get rid of it. Which leads regulars uses to believe that they need to renew it or deal with it's popups. 

Been their tactic for years

Fuck them. They can die out. 

Lenovo too. 

What's wrong with lenovo?

Link to comment
Share on other sites

Link to post
Share on other sites

What's wrong with lenovo?

They had this adware/spyware bundled in their systems.

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

Norton, which is made by Symantec, is shit, so by extension, Symantec is shit.

Symantec's security research and analysis half is good, but their business half... ugh, I'd rather use the built-in antivirus in Windows 8/10.

Link to comment
Share on other sites

Link to post
Share on other sites

What's wrong with lenovo?

The thinkpad 2-1 I had was also bar none the worst computer ive ever used with its faults and not working as it should.

System Specs

CPU: Ryzen 5 5600x | Mobo: Gigabyte B550i Aorus Pro AX | RAM: Hyper X Fury 3600 64gb | GPU: Nvidia FE 4090 | Storage: WD Blk SN750 NVMe - 1tb, Samsung 860 Evo - 1tb, WD Blk - 6tb/5tb, WD Red - 10tb | PSU:Corsair ax860 | Cooling: AMD Wraith Stealth  Displays: 55" Samsung 4k Q80R, 24" BenQ XL2420TE/XL2411Z & Asus VG248QE | Kb: K70 RGB Blue | Mouse: Logitech G903 | Case: Fractal Torrent RGB | Extra: HTC Vive, Fanatec CSR/Shifters/CSR Elite Pedals w/ Rennsport stand, Thustmaster Warthog HOTAS, Track IR5,, ARCTIC Z3 Pro Triple Monitor Arm | OS: Win 10 Pro 64 bit

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×