Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not sure why this is downvoted. It is correct.


Because it's wrong. The very post GP linked explicitly says that Symantec certs issued before June 1, 2016 would stop functioning in Chrome 66.


Chrome also blacklisted certs issued after June 1, 2016.


I understand if you don't want to reveal your organization affiliations, but if this was widespread, it should have been discussed somewhere with more specifics. Can you link to a discussion anywhere with more specific examples?

We had a bunch of RapidSSL certs in-use internally, and were rather pokey in replacing them since they were less-critical internal certs. Everything with the deprecation warnings were exactly as expected and announced.

I follow Mozilla's dev Security list and the CAB Forum mailing lists fairly regularly, can't find any discussions about Google deviating from their announced plan.


You can imagine how ridiculous this sounds right? If Google had blacklisted these certs in April as you claim, would that have not been a massive shitshow for everyone involved, and would have been on the top of HN?




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: