If you can’t access a HTTPS website – like Wikipedia – today, it’s because CA GlobalSign completely screwed up http://www.theregister.co.uk/2016/10/13/globalsigned_off/ …pic.twitter.com/dAaHjtl1G4
When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more
It’s a little more complex than that – it involves cross-root certs. But it may well take FOUR days to fix. Here’s GlobalSign’s statementpic.twitter.com/RZYBvQuSid
@TheRegister @SwiftOnSecurity reads to me like a bug in browser revocation processing. Not the case?
@tpw_rules @swiftonsecurity Yeah, also thinking that too.
@TheRegister @SwiftOnSecurity I hope they would have tested before pulling the trigger, but If that info is right, not technically at fault
@tpw_rules @swiftonsecurity Can you think of a common SSL/TLS bug that could cause this?
@TheRegister @SwiftOnSecurity no idea. Was referring to bottom of 2nd paragraph. It blames the browsers
@tpw_rules @swiftonsecurity Yet Kaspersky and other applications are affected - there would have to be a common client-side bug for this
@TheRegister @SwiftOnSecurity ah, you've stumped me
@TheRegister smells fishy, are you sure it’s not an attack of some sort?
@jzdziarski Could be, could be. We’re waiting for GlobalSign to pick up the phone after offering us an interview
@TheRegister more sounds like there were two paths to the root, one was revoked but software failed to follow other path.
@TheRegister well, they didn’t revoke them intentionally… the mechanism that does this simply malfunctioned.
@TheRegister Oh dear, we use that at work... Tomorrow will be busy...
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.