Welcome to WebmasterWorld Guest from 54.80.185.137

Forum Moderators: open

Featured Home Page Discussion

Webmasters: Distrust of Symantec PKI in Chrome 66

     
11:48 am on Apr 5, 2018 (gmt 0)

Administrator from GB 

WebmasterWorld Administrator engine is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month Best Post Of The Month

joined:May 9, 2000
posts:25199
votes: 685


As previously notified, Google is deprecating trust in Symantec-issued validation certificates. See Google To Deprecate and Remove Trust From 30,000 Symantec-issued Extended Validation Certificates [webmasterworld.com]
An the notification that Chrome 66 will remove trust for pre-june 2016 certificates.
It seemed a long way away when first announced, but now, Google says it may already be impacting users, and wants webmasters to take action [security.googleblog.com].

Chrome 66 To Remove Trust For Symantec-issued Certificates Pre June 2016 [webmasterworld.com]

This is what users will see.
https://2.bp.blogspot.com/-Sok6Apvb6CA/WqA2DO6HRQI/AAAAAAAAAko/ju9rLfHgZMMy_u3lNbFfvUyjh7YNzEZFwCLcBGAs/s640/interstitial%2B-%2B1.png
11:57 am on Apr 5, 2018 (gmt 0)

Senior Member

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month

joined:Sept 25, 2005
posts:1753
votes: 254


An analysis [arkadiyt.com] of the top 1M domains in February suggests about 0.6% of sites will be affected by the change in M66, and 4.6% by those in M70. Pretty significant numbers, and it included some heavy hitters like icloud.com, blackbarry.com and tesla.com.

I'm afraid this will fly under the radar of many of those webmasters... until their traffic plummets.
4:56 pm on Apr 5, 2018 (gmt 0)

Senior Member

WebmasterWorld Senior Member topr8 is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Apr 19, 2002
posts:3367
votes: 41


>>I'm afraid this will fly under the radar of many of those webmasters... until their traffic plummets.

i had some certs that were effected and i've been receiving quite regular emails (from Symantec) reminding me of the issue and showing me how to upgrade my certs (for free), they also say they have a 24/7 helpline if you need help with this issue.

so to be fair they are warning webmasters ... but i guess many are ignoring the warnings! or in the case of bigger organisations than me (not difficult) ... the mechanics of making what is a simple change are very ponderous.
5:31 pm on Apr 5, 2018 (gmt 0)

Administrator from GB 

WebmasterWorld Administrator engine is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month Best Post Of The Month

joined:May 9, 2000
posts:25199
votes: 685


Wait for the calls that Google is not sending traffic.
This one sounds an easy fix.
6:28 pm on Apr 5, 2018 (gmt 0)

Moderator from US 

WebmasterWorld Administrator keyplyr is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Sept 26, 2001
posts:11112
votes: 662


I wonder how this will get gamed.