Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The public notice the article links to doesn't say anything about "other purposes". Their headline is "Discontinued Use of VeriSign G1 Roots". It does comment about continued use of that cert for code signing, likely due to legacy trust stores.

To me, it sounds like they're trying to consolidate their image under the "Symantec" brand by moving browsers off the old "Verisign" root, but they don't think they can move code signing. However, since code signing is outside the scope of CAB, they're stopping their audits.

Or at least, that's my take.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: