Skip to main content

Google issues ultimatum to Symantec over unauthorized HTTPS certificates

Google has laid down an ultimatum for Symantec — be fully transparent about the issuing of your security certificates or sites that use Symantec certificates will be deemed unsafe by Google Chrome.

In September Symantec revealed in a report that it had fired a number of employees for issuing unauthorized TSL certificates for domain names to companies that did not own them.

Recommended Videos

This meant that they could have been used to copycat HTTPS-protected websites, including those of Google’s. Cyber-criminals could use the certificates to impersonate highly-reputable sites and go undetected.

Please enable Javascript to view this content

Initially, Symantec said that 23 certificates were issued, but Google has disputed this number, saying it is much higher. Following further examination, Symantec said that there were a further 164 certificates over 76 domains and 2,458 certificates for domains not yet registered.

In a blog post, Google’s Ryan Sleevi called for the details of Symantec’s investigation to be made public and transparent in order to understand why the number of certificates issued was under estimated. This involves detailed information on how the company will prevent this from happening again as well as what its methods will be.

Sleevi has also called for Symantec to ensure that all SSL certificates, as of June 1 2016, are issued in accordance with Certificate Transparency, a public audit log.

“After this date, certificates newly issued by Symantec that do not conform to the Chromium Certificate Transparency policy may result in interstitials or other problems when used in Google products,” wrote Sleevi.

If Symantec, and possibly any other certificate issuer, doesn’t follow these guidelines, it runs the risk of its SSL certificates being flagged as unsafe or unsecure, which would send a bad message to any user trying to access sites using them through Chrome.

In response, Symantec has said the issue was caused by a testing error. It stated that it has revoked and blacklisted the certificates in question and said that there had been no harm caused to any users or organizations.

“To prevent this type of testing from occurring in the future, we have already put additional tool, policy and process safeguards in place, and announced plans to begin Certificate Transparency logging of all certificates,” said the statement. “We have also engaged an independent third-party to evaluate our approach, in addition to expanding the scope of our annual audit.”

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Wildfire smoke prompts Google to issue work-from-home advisory
google-office

Google has told its employees in the northeast of the U.S. to work from home in order to limit their exposure to smoke drifting in from hundreds of wildfires in Canada.

Dramatic news images of New York City disappearing in a smoky haze on Wednesday showed the extent of the dire air quality as fires in eastern Canada continue to burn. Data later revealed that the air quality in the metropolis on Wednesday was the worst of any city globally.

Read more
Google just thwarted the largest HTTPS DDoS attack in history
A depiction of a hacker breaking into a system via the use of code.

Google has confirmed that one of its cloud customers was targeted with the largest HTTPS distributed denial-of-service (DDoS) attack ever reported.

As reported by Bleeping Computer, a Cloud Armor client was on the receiving end of an attack that totaled 46 million requests per second (RPS) at its peak.

Read more
Google Meet just got a massive advantage over Zoom and Teams
Google Meet's stylized background show movement glitches.

If you've ever tried Google Meet's visual effects, you already know that moving around can create glitches and gaps at the edges where the foreground object (you) meets the stylized background. The computer's confusion about which part of a webcam image belongs in the front and which goes in the back is getting a huge upgrade with the latest Google Meet update.

The issue with the old version is that many computers lack the processing power to extract depth information from a webcam. That means Google Meet might not find the edges well enough to begin with, and it is often slow to update whenever you move. It's not as noticeable when using a blur effect but can spoil the experience when you apply a stylized background. Nothing wrecks a peaceful nature background more than a pixelated hand with pieces missing when you wave.

Read more