It's a pity Symantec (with all their sub-brands) is used by such a large number of sites that it's not feasible to simply remove them from the trust store completely. Between the cases of misissuance, misleading marketing and their attitude with regards to deprecating unsafe practices and technology, I have absolutely zero trust in their ability to operate a certificate authority safely. This is just the final nail in the coffin for me.
It would be interesting if browsers started stochastically rejecting their certificates. Maybe only a few percent chance today, so a simple reload will solve. Prudent sites would see the writing on the wall and migrate away. As time goes on, the pain ramps up.
It's a pity Symantec (with all their sub-brands) is used by such a large number of sites that it's not feasible to simply remove them from the trust store completely. Between the cases of misissuance, misleading marketing and their attitude with regards to deprecating unsafe practices and technology, I have absolutely zero trust in their ability to operate a certificate authority safely. This is just the final nail in the coffin for me.
Perhaps there could be an untrust store, for CA's that should not be in the signing chain.
There is one: https://blog.filippo.io/untrusting-an-intermediate-ca-on-os-... (linked from tweet) That's OS X, but probably every major trust store can do this.
It would be interesting if browsers started stochastically rejecting their certificates. Maybe only a few percent chance today, so a simple reload will solve. Prudent sites would see the writing on the wall and migrate away. As time goes on, the pain ramps up.