December 15, 2015 By Larry Loeb 2 min read

Earlier this month, Symantec announced that it will stop using the VeriSign G1 root certificate (Class 3 Public Primary CA) it had previously been using to issue public code signing and TLS/SSL certificates. In response, Google said it would not recognize the newly unsupported certificate in Chrome, Android and other products.

The underlying problem had been ongoing since October, when Google’s engineers found 164 certificates over 76 domains and 2,458 certificates issued for domains that were never registered by Symantec. Google was directly affected by this. Symantec argued that the certificates were only used for testing purposes and that they posed no risk to users.

At the time, Google wanted Symantec to show adherence to WebTrust Principles and Criteria for Certification Authorities, as well as undergo a security audit. While it announced it would not use the G1 certificate for public use, Symantec said it would still use it for other purposes. Evidently, Google thought this wasn’t such a good idea.

As Google engineer Ryan Sleevi put it on the Web giant’s security blog, “As this root certificate will no longer adhere to the CA/Browser Forum’s Baseline Requirements, Google is no longer able to ensure that the root certificate, or certificates issued from this root certificate, will not be used to intercept, disrupt or impersonate the secure communication of Google’s products or users.”

Essentially, it seems Google is saying Symantec requested this browser change in the trustworthiness of its certificates. This seems to be the course Symantec would request if it won’t be using that certificate for public-facing purposes.

Symantec has indicated to Google that it does not believe its customers, who are the operators of secure websites, will be affected by this removal. Furthermore, Symantec has also indicated that, to the best of its knowledge, it does not believe customers who attempt to access sites secured with Symantec certificates will be affected by this.

However, an untrusted certificate used by a site would render users unable to perform secure downloads using the HTTPS protocol when the browsers that reject it are employed. The browsers also wouldn’t be able to identify the site as being legitimate. Unless the certificates previously supplied by Symantec are replaced by newer certificates that the browsers will accept as valid, it seems there will be an issue.

How other browsers will treat Symantec’s certificates remains to be seen. Given the revocation of trust, however, others may follow Google’s lead.

More from

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

What’s behind unchecked CVE proliferation, and what to do about it

4 min read - The volume of Common Vulnerabilities and Exposures (CVEs) has reached staggering levels, placing immense pressure on organizations' cyber defenses. According to SecurityScorecard, there were 29,000 vulnerabilities recorded in 2023, and by mid-2024, nearly 27,500 had already been identified.Meanwhile, Coalition's 2024 Cyber Threat Index forecasts that the total number of CVEs for 2024 will hit 34,888—a 25% increase compared to the previous year. This upward trend presents a significant challenge for organizations trying to manage vulnerabilities and mitigate potential exploits.What’s behind…

Quishing: A growing threat hiding in plain sight

4 min read - Our mobile devices go everywhere we go, and we can use them for almost anything. For businesses, the accessibility of mobile devices has also made it easier to create more interactive ways to introduce new products and services while improving user experiences across different industries. Quick-response (QR) codes are a good example of this in action and help mobile devices quickly navigate to web pages or install new software by simply scanning an image.However, legitimate organizations aren’t the only ones…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today