But as the other poster says, this probably wasn't leaked at all.
More than half of the CAs have publicly violated trust at some point. The governments of the US and China, who are arguably the biggest threats to HTTPS, still have CAs.
While I agree with you wholeheartedly, it doesn't look like either incompetence or malice vis a vis security are substantial enough justifications for the browser makers to pull the plugs here.
This is just semantics, though. I think everyone agrees they done bad.
> As much as we hate to lose valuable colleagues, we are the industry leader in online safety and security, and it is imperative that we maintain the absolute highest standards. At the end of day, we hang our hats on trust, and that trust is built by doing what we say we’re going to do.
Wow.
I have to say that I respect that decision. Without knowing the circumstances, I have to say that willful disregard for security policy while handling materials as sensitive as a CA cert is indeed not something I'd want to see from employees at a CA.
Cf. the child-porn case also on the front page now (kid has picture of self on phone; https://news.ycombinator.com/item?id=10247764). It's probably also based on some kind of zero-tolerance policy or campaign promise.
Had the announcement merely referred to the "thoughtful review process" (which is good) but not then nullified the meaning of that process with a thoughtless "no compromise" standard (which is silly), then it'd be at least eligible for respect.
the java server pages application that serves the main site has extended validation https://www.symantec.com/index.jsp
but connect doesn't. It seems like https://www.symantec.com/connect/ redirects to http://www.symantec.com/connect/
r.port="https"===o[0]?"443":"80"
Why can't Symantec afford to put ssl on its connect site? It is not like they have to pay anyone for a certificate...
Symantec for some reason created google certificate internally and then someone used chrome