Google Plans to Reduce Trust in Symantec's TLS Certificates Due to 'Continual Misissuance'

Advertisement
By Tasneem Akolawala | Updated: 27 March 2017 18:21 IST
Highlights
  • Google to reduces trust in Symantec certificates
  • This is due to failure in properly validating certificates
  • Symantec says the claims are 'exaggerated'

Google's Chrome team is unhappy with the loose way in which Symantec issues transport layer security (TLS) certificates, and is considering incremental distrust Symantec TLS certificates moving forward. This planned step was announced by Google due to "a continually increasing scope of misissuance" from Symantec. It plans to reduce the trust on the biggest issuers of security certificates gradually, as well as revoke recognition of their extended versions for a year.

Ravi Sleevi, a software engineer on the Google Chrome team, wrote on the Blink online forum that the Chrome developers "no longer have confidence in the certificate issuance policies and practices of Symantec over the past several years."

Sleevi has proposed a reduction in the accepted validity period of newly issued Symantec-issued certificates to nine months or less. Furthermore, he also proposes the removal of recognition of the Extended Validation status of all certificates issued by Symantec for at least a year. This will put the company into a lot of pressure, as its customers will then demand a refund. Lastly, Sleevi also proposed "incremental distrust, spanning a series of Google Chrome releases, of all currently-trusted Symantec-issued certificates, requiring they be revalidated and replaced."

Advertisement

Taking into account the last 30,000 certificates issued by Symantec since January 19, Google claims that the security firm hasn't done enough to verify the site, and ensure that the certificates are issued correctly. "Root certificate authorities are expected to perform a number of critical functions commensurate with the trust granted to them. This includes properly ensuring that domain control validation is performed for server certificates, to audit logs frequently for evidence of unauthorized issuance, and to protect their infrastructure in order to minimize the ability for the issuance of fraudulent certs," Sleevi explains in the forum further claiming that Symantec has failed to follow these principles.

Advertisement

Symantec, on the other hand, strongly opposes these accusations and calls them "exaggerated and misleading", as per a BBC report. The company claimed that out of the 30,000, only 127 were identified as wrongly issued, and that it feels that Google has 'singled it out' over the other certificate issuers that are also at fault. "We are open to discussing the matter with Google in an effort to resolve the situation in the shared interests of our joint customers and partners," Symantec told BBC in a statement.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy F17 5G With 5,000mAh Battery Launched in India
  2. Oppo F31 Series Specifications Confirmed Ahead of India Launch
  3. Flipkart BBD Deal: iPhone 16 Pro Max Under Rs. 90,000
  4. OTT Releases This Week: Coolie, Saiyaara, a Tamannaah Bhatia Web Series
  5. Samsung Galaxy S25 FE Tipped to Go On Sale At This Price in India
  6. iPhone 14 Under Rs. 40,000: Flipkart's Big Billion Days Deal Revealed
  7. Experts Warn Against Charlie Kirk Tokens Amidst Backlash, Volatility
  8. You Can Now Sign Up to Test Xiaomi's HyperOS 3 Update
  9. Amazon's 10-Minute Delivery Service is Now Available in This City
  10. Google Updates Gemini App's Prompt Bar With an Open-Box Design
  1. SpaceX Falcon 9 Launches 21 Satellites for US Military’s New Communications Network
  2. NASA Uses Rocky Mountain Helicopter Drills to Prepare Astronauts for Artemis Moon Missions
  3. NASA’s Perseverance Rover Finds Potential Signs of Life in Mars Rock Sample
  4. iPhone 14 Under Rs. 40,000: Flipkart's Big Billion Days Sale Deal Revealed
  5. Forget iPhone 17 Pro, Get the iPhone 16 Pro Max for Under Rs. 90,000 in Flipkart's Big Billion Days Sale
  6. Supermoon 2025: When Is the Next Full Moon Lighting Up the Sky
  7. New Black Hole Merger Gives Clearest Test of Einstein’s Relativity
  8. Only Murders in the Building Season 5 Now Streaming Online: Know When and Where to Watch
  9. Sony Launches PlayStation Family App on iOS, Android for Parental Controls on Gaming Activity
  10. Itel Super 26 Ultra Launched With 6.8-Inch Display, 6,000mAh Battery: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.