ISC StormCast for Monday, March 27th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 March 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 27th, 2017 edition of the Sandton and Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:12.3 | Over the last couple of years, there were a couple of issues where Symantec was blamed by Google for issuing bad certificates. |
| 0:21.6 | Now, Symantec often stated that these were test certificates. |
| 0:25.6 | They never saw any actual use outside of Symantex labs, but probably somewhat rightfully. |
| 0:33.6 | So Google said that the ability of semantic employees to create these certificates |
| 0:39.9 | can be seen as a breakdown in controls that Symantec should have in place in order to |
| 0:47.1 | implement a trusted certificate issuing process. |
| 0:51.3 | While I haven't been any new issues, Google is still not happy with Symantex response and |
| 0:57.7 | is now threatening to face out trusting Symantex certificate authority certificates |
| 1:04.2 | for future versions of Google Chrome. |
| 1:08.1 | Now this will be a face-out process. It will span a number of Google Chrome releases. |
| 1:14.6 | And extended validation certificates being issued by Symantec will no longer be recognized as extended validation certificates. |
| 1:23.6 | So they will work just like any normal certificate. This is a pretty drastic step and according to Google's post, |
| 1:32.3 | anywhere between 30 and 40% of certificates or requests to HDPS websites |
| 1:39.3 | and may be affected by this particular measure. |
| 1:45.0 | So what this means to you if you're using SSL certificates anywhere in your environment, |
| 1:50.0 | the ones that will be affected here are the ones that are using for HDPS, |
| 1:56.0 | because at this point this will only affect Google Chrome. |
| 2:00.0 | So don't worry too much about IMAP and other |
| 2:02.9 | certificates like that. If certificates are issued by Symantec, then you may have to have them |
| 2:10.9 | reissued at some point in the future. Wouldn't rush it, but start at least enumerating the certificate and be aware |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

