Google drops the boom on WoSign, StartCom certs for good

(credit: Michael Rosenstein) Last August, after being alerted by GitHub’s security team that the certificate authority WoSign had errantly issued a certificate for a GitHub domain to someone other than GitHub, Google began an investigation in collaboration with the Mozilla Foundation and a group of security professionals into the company’s certificate issuance practices. The investigation uncovered […]

Google takes Symantec to the woodshed for mis-issuing 30,000 HTTPS certs

Enlarge (credit: Nyttend) In a severe rebuke of one of the biggest suppliers of HTTPS credentials, Google Chrome developers announced plans to drastically restrict transport layer security certificates sold by Symantec-owned issuers following the discovery they have issued more than 30,000 certificates. Effective immediately, Chrome plans to stop recognizing the extended validation status of all […]