December 15, 2015 By Larry Loeb 2 min read

Earlier this month, Symantec announced that it will stop using the VeriSign G1 root certificate (Class 3 Public Primary CA) it had previously been using to issue public code signing and TLS/SSL certificates. In response, Google said it would not recognize the newly unsupported certificate in Chrome, Android and other products.

The underlying problem had been ongoing since October, when Google’s engineers found 164 certificates over 76 domains and 2,458 certificates issued for domains that were never registered by Symantec. Google was directly affected by this. Symantec argued that the certificates were only used for testing purposes and that they posed no risk to users.

At the time, Google wanted Symantec to show adherence to WebTrust Principles and Criteria for Certification Authorities, as well as undergo a security audit. While it announced it would not use the G1 certificate for public use, Symantec said it would still use it for other purposes. Evidently, Google thought this wasn’t such a good idea.

As Google engineer Ryan Sleevi put it on the Web giant’s security blog, “As this root certificate will no longer adhere to the CA/Browser Forum’s Baseline Requirements, Google is no longer able to ensure that the root certificate, or certificates issued from this root certificate, will not be used to intercept, disrupt or impersonate the secure communication of Google’s products or users.”

Essentially, it seems Google is saying Symantec requested this browser change in the trustworthiness of its certificates. This seems to be the course Symantec would request if it won’t be using that certificate for public-facing purposes.

Symantec has indicated to Google that it does not believe its customers, who are the operators of secure websites, will be affected by this removal. Furthermore, Symantec has also indicated that, to the best of its knowledge, it does not believe customers who attempt to access sites secured with Symantec certificates will be affected by this.

However, an untrusted certificate used by a site would render users unable to perform secure downloads using the HTTPS protocol when the browsers that reject it are employed. The browsers also wouldn’t be able to identify the site as being legitimate. Unless the certificates previously supplied by Symantec are replaced by newer certificates that the browsers will accept as valid, it seems there will be an issue.

How other browsers will treat Symantec’s certificates remains to be seen. Given the revocation of trust, however, others may follow Google’s lead.

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today