Article RYK4 Still fuming over HTTPS mishap, Google makes Symantec an offer it can’t refuse

Still fuming over HTTPS mishap, Google makes Symantec an offer it can’t refuse

by
Dan Goodin
from Ars Technica - All content on (#RYK4)
godfather-640x360.jpg

Google has given Symantec an offer it can't refuse: give a thorough accounting of its ailing certificate authority process or risk having the world's most popular browser-Chrome-issue scary warnings when end users visit HTTPS-protected websites that use Symantec credentials.

The ultimatum, made in a blog post published Wednesday afternoon, came five weeks after Symantec fired an undisclosed number of employees caught issuing unauthorized transport layer security certificates. The mis-issued certificates made it possible for the holders to impersonate HTTPS-protected Google webpages.

Symantec first said it improperly issued 23 test certificates for domains owned by Google, browser maker Opera, and three other unidentified organizations without the domain owners' knowledge. A few weeks later, after Google disputed the low number, Symantec revised that figure upward, saying it found an additional 164 certificates for 76 domains and 2,458 certificates for domains that had never been registered. The mis-issued certificates represented a potentially critical threat to virtually the entire Internet population because they made it possible for the holders to cryptographically impersonate the affected sites and monitor communications sent to and from the legitimate servers.

Read 7 remaining paragraphs | Comments

index?i=oKrdC3jZV6s:QZe_Q0z_X98:V_sGLiPB index?i=oKrdC3jZV6s:QZe_Q0z_X98:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments