/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Chrome to immediately stop recognizing extended validation status of Symantec-issued certs and gradually nullify all currently valid certs of Symantec-owned CAs

Saturday, March 25, 2017 Sean Michael Kerner / eWeek : Google Threatens to Distrust Symantec SSL/TLS Certificates Lucian Constantin / Macworld : To punish Symantec, Google may distrust a third of the web's SSL certificates Fahmida Y. Rashid / InfoWorld : Google to Symantec: We don't trust you anymore WebProNews : Google Spanks Symantec for Mis-issuing 30,000 EV Certificates Spyware Sucks : Big news re Google and Symantec issued EVs Tweets: Will Dormann / @wdormann : The company that has issued over 1/3 HTTPS certificates on the Internet has shown that it cannot be trusted to issue certificates. http://twitter.com/...

Ars Technica Dan Goodin

Context & Ripple Effects

This is the escalation of a two-year standoff: back in October 2015, Google gave Symantec an ultimatum to fully account for misissued google.com certificates or see its TLS certificates flagged as unsafe in Chrome — and now, with roughly a third of the web's HTTPS certificates reportedly issued under Symantec-owned CAs, Chrome is acting on it.

The move also fits a pattern of browser-enforced discipline: Chrome previously banished a Chinese certificate authority for breach of trust in 2015, and by July 2017 Google moved to completely distrust WoSign and StartCom over wrongly issued certs. Symantec is the largest target yet for the same enforcement mechanism.

First-order effects

  • Symantec's extended-validation green-bar status disappears in Chrome immediately, and every currently valid certificate from Symantec-owned CAs is on a path to being nullified — forcing the large share of sites relying on them to reissue from another CA.

Second-order effects

  • Rival certificate authorities absorb reissue demand at scale, while other browser vendors face pressure to match Chrome's distrust or leave their users seeing inconsistent trust indicators for the same certificates.

Third-order effects

  • If the sequence holds — CNNIC, then WoSign and StartCom, now Symantec — Chrome's distrust decisions become the de facto regulatory mechanism for the entire CA ecosystem, with browser vendors rather than auditors deciding which issuers survive.

The trend: Certificate authority trust is shifting from audit-based self-governance to browser-vendor enforcement, with Chrome's distrust decisions setting the industry standard.