Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / To punish Symantec, Google can also distrust a third of the web's SSL certificate

To punish Symantec, Google can also distrust a third of the web's SSL certificate

Latest Govt. Jobs 11:49:00 News Edit
Google is planning severe sanctions against Symantec's certificate authority.

Google is considering a harsh punishment for repeated incidents in which Symantec or its certificate resellers improperly issued SSL certificates. A proposed plan is to force the company to replace all of its customers’ certificates and to stop recognizing the extended validation (EV) status of those that have it.
According to a Netcraft survey from 2015, Symantec is responsible for about one in every three SSL certificates used on the web, making it the largest commercial certificate issuer in the world. As a result of acquisitions over the years the company now controls the root certificates of several formerly standalone certificate authorities including VeriSign, GeoTrust, Thawte and RapidSSL.
SSL/TLS certificates are used to encrypt the connections between browsers and HTTPS-enabled websites and also to verify that users are actually visiting the websites they intended to and not spoofed versions. These certificates are issued by organizations known as certificate authorities that are trusted by default in browsers and operating systems.
The process of issuing and managing certificates is governed by rules created by the CA/Browser Forum, an organization whose members include browser vendors and certificate authorities. When those rules are violated, browser and OS vendors can revoke trust in the offending certificates and sanction the responsible certificate authorities, going as far as kicking them out of their root certificate stores.
Google says that an investigation into a recent incident indicates that Symantec has not upheld security practices expected of certificate authorities, such as validating domain control,  auditing logs for evidence of unauthorized issuance, and minimizing the ability for the issuance of fraudulent certificates.
If Google’s plan is put into practice, millions of existing Symantec certificates will become untrusted over the next 12 months in Google Chrome. This will be a gradual process where every new Chrome release will distrust a new batch of certificates starting with Chrome 59,  which will revoke trust in certificates that have a validity period of over 33 months.
This will put enormous pressure on Symantec, as the company will have to contact all customers, validate their identity and the ownership of their domains all over again, and replace their existing certificates with new ones, most likely at no cost.
Some companies will likely have problems replacing their certificates on such short notice, as they might be used in payment terminals and other hard-to-reach embedded devices.
In addition to that, Symantec might have to refund customers who paid for EV certificates that will no longer be recognized as such in Chrome, since their value would be significantly reduced. The ban on Symantec EV certificates will last for at least one year.
All replacement certificates issued by Symantec to customers will need to have a validity period of nine months or less in order to be trusted in Chrome. This is likely to cause further problems for some large companies, which won’t be able to easily replace their certificates every nine months.
It’s safe to say that Google’s sanctions might have a significant impact on Symantec’s SSL business, as the company is likely to lose customers who won’t be willing to put up with these restrictions and will take their business to a different certificate authority (CA).
Browser vendors have punished CAs before for improperly issuing certificates—or “misissuing” them, in industry parlance—but never on this scale and with an impact so large on the ecosystem. Some people have always wondered if browser vendors can really take drastic sanctions against the world’s largest CAs, or whether those authorities are simply too big to fail.
The reason for this unprecedented punishment seems to be repeated incidents of misissued certificates at Symantec that have come to light over the past few years, some of which the company failed to identify on its own despite internal and external audits. The latest case was uncovered this year and involved 127 certificates issued with bogus information or without proper domain ownership verification by a Symantec partner that operated as a registration authority (RA).
According to Google, that investigation calls into question the validity of at least 30,000 certificates issued by Symantec partners over a period spanning several years. However, Symantec disputes that number.
“Symantec allowed at least four parties access to their infrastructure in a way to cause certificate issuance, did not sufficiently oversee these capabilities as required and expected, and when presented with evidence of these organizations’ failure to abide to the appropriate standard of care, failed to disclose such information in a timely manner or to identify the significance of the issues reported to them,” Google’s Ryan Sleevi said in a post on the Chrome development mailing list.
This and past incidents have led Google to “no longer have confidence in the certificate issuance policies and practices of Symantec over the past several years,” Sleevi said.
Symantec strongly objected to Google’s plan and criticized its publication. It also described Google’s remarks about the company’s past misissuances as “exaggerated and misleading.”
“This action was unexpected, and we believe the blog post was irresponsible,” the company said in a blog post Friday. “We hope it was not calculated to create uncertainty and doubt within the Internet community about our SSL/TLS certificates.”
The claim about the 30,000 certficates is not true and the 127 certificates that have been confirmed as misissued did not result in any consumer harm, Symantec said, adding that the relationship with the partner responsible for the incident has been terminated and that its entire RA program has been discontinued.
“While all major CAs have experienced SSL/TLS certificate mis-issuance events, Google has singled out the Symantec Certificate Authority in its proposal even though the mis-issuance event identified in Google’s blog post involved several CAs,” Symantec said.
The company will work to minimize any potential disruption caused by Google’s proposal if it goes forward, but is open to discussing the matter with Google and finding a mutually agreed-on solution.
Meanwhile, Mozilla, which manages its own root certificate program, is also considering sanctions for Symantec and might have to align them with Google’s.
“Now that Google have announced their action, it is unavoidable to note that it can be preferable for two root stores considering action against a CA to take broadly parallel approaches, so that the CA is not doubly penalised for the same actions,” Mozilla’s Gervase Markham wrote on the organization’s security policy mailing list.
However, Markham noted that Google’s plan is “at the strong end” of the options he was considering and that calibrating the level of response, which has to take into account previous precedents and sanctions against other CAs, is a difficult process.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Vodafone partners with Tecno to off...

LG G7 with iPhone X-like notch

Oppo F7 India launch confirmed
To punish Symantec, Google can also distrust a third of the web's SSL certificate To punish Symantec, Google can also distrust a third of the web's SSL certificate Reviewed by Latest Govt. Jobs on 11:49:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...

Random Posts

  • Xiaomi Mi 6 to launch in March, says company’s co-founder
    Xiaomi Mi 6 to launch in March, says company’s co-founder
    16.01.2017 - 0 Comments
    *Representative Image NEW DELHI: Xiaomi has been rumoured to launch its next flagship…
  • 3 Ways A Romantic Relationship Can Spark Your Spiritual Awakening
    3 Ways A Romantic Relationship Can Spark Your Spiritual Awakening
    07.08.2016 - 0 Comments
    In this post, Shelly Bullard gives us a peek into the way romantic relationships can facilitate real…
  • The secret story of how the LG G6 leaked online
    The secret story of how the LG G6 leaked online
    15.02.2017 - 0 Comments
    If there’s one thing that’s been a constant over the last decade in the technology industry, it’s the…
  • what is Apple Clips and the way to use it?
    what is Apple Clips and the way to use it?
    08.04.2017 - 0 Comments
    Clips is a new app developed by Apple to help you customize your photos and videos before…
  • How to use Linux Commands
    How to use Linux Commands
    10.02.2017 - 0 Comments
    It won't be long after starting to use Linux that you ask a question and the answer begins…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Google's Android hacking contest fails to draw exploits
    Six months ago ...
  • This week in video games: Oculus founder departs, Mad Catz shutters, Battlefield 1 gets friendly
    In the grand ...
  • The music that changed gaming forever From 8-bit to Chiptune
    Here’s a ...
  • Paytm Hostel Booking Offer HTL40 – Get 40% cashback On No Minimum Order Value (2 Times)
    Paytm Paytm Hostel ...

Random Posts

  • How to Take Faster Screenshots on the PlayStation 4
    How to Take Faster Screenshots on the PlayStation 4
    11.02.2017 - 0 Comments
    When you’re caught up in your favorite game—you know, the one that you can play over and over again, and…
  • HTC reveals HTC U Ultra and U Play price in UK
    HTC reveals HTC U Ultra and U Play price in UK
    15.02.2017 - 0 Comments
    HTC unveiled its latest flagship smartphone HTC U Ultra along with a…
  • 11.02.2016 - 0 Comments
  • 10 simple And herbal approaches To fight Thyroid-caused Hair Loss
    10 simple And herbal approaches To fight Thyroid-caused Hair Loss
    17.05.2016 - 0 Comments
    Hair loss is pretty not unusual in girls. even as guys are similarly affected by hair loss, women percentage…
  • Apple iPhone 6 (32GB): Gold colour variant now available in India at Rs 26,999 via Amazon India
    Apple iPhone 6 (32GB): Gold colour variant now available in India at Rs 26,999 via Amazon India
    19.08.2017 - 0 Comments
    Apple has taken wraps off the iPhone 6 in a new gold colour option in India. Amazon is also…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!