Live data from Hacker News

Windows Certificate Manager does not display the complete trust list

hexatomium.github.io

31–40 of 103 posts

Re: Windows Certificate Manager does not display the complete trust list

#31
post #22

One feature of Windows is defaulting to not showing messy complexity to the user. The other feature is defaulting to backward compatibility. Combined, this means that Windows often has more than two data stores for some aggregate feature [e.g. web browser security, software configuration etc.] as new versions of Windows implement these features in more robust ways. So yeah there are two or more places where certifica…

"Typical users only care about the abstraction of web security so that's what Windows surfaces." Typical users do not open certmgr.msc

[deleted]

Re: Windows Certificate Manager does not display the complete trust list

#32

One feature of Windows is defaulting to not showing messy complexity to the user. The other feature is defaulting to backward compatibility. Combined, this means that Windows often has more than two data stores for some aggregate feature [e.g. web browser security, software configuration etc.] as new versions of Windows implement these features in more robust ways. So yeah there are two or more places where certifica…

The problem with your argument is that this is an administrative GUI that isn't even normally presented to end users unless you search for it or know how MMC snap-ins work. It is a power-user interface by all measure.

And while Microsoft does simplify UIs for end users, they don't typically do the same for administrative content (just look at anything in the Admin Tools, or MMC snap-ins, no sugar coating there).

Your argument about backwards compatibility is at best confusing. What does the data stores utilised have to do with UI representations of the same? I can name numerous examples where things changed behind the scenes and the UI was just updated to support it (e.g. Disk Manager now supports ESP, and exFat, same UI, ConHost now supports Powershell, same UI, Defrag now supports Trim for SSDs, same UI, etc).

> So yeah there are two or more places where certificates are stored. Typical users only care about the abstraction of web security so that's what Windows surfaces.

No, it doesn't. As the blogpost clearly shows it doesn't "surface" all root CAs usable by websites.

> Application developers should choose the new store for new applications. Existing applications can use the old method.

Huh? What do application developers have to do with this? I don't see the connection. This isn't talking about the custom root CAs you may install, it is talking about Microsoft's list of preinstalled ones.

> System administrators and security consultants should make themselves familiar with all the documentation and double their rates.

Please link to the documentation about this on Microsoft's site.

> Bloggers, however, are still free to write linkbait headlines using the Windows bashing meme.

Aside from the word "lying" (which is emotive), the title is largely accurate. Windows does mislead about installed trusted root CAs. And nothing you've said in this apologist answer has come close to addressing that, you're just dancing around it.

Re: Windows Certificate Manager does not display the complete trust list

#33
post #8

Earlier quoted context omitted.

What is "better" about MS word than google docs? The only reason I see to use word is if you're using files from 1999 that don't work anywhere else. Google docs is a much simpler system, especially for places like schools because of the "cloud" nature of it. Google docs has all the features the average person needs. MSWord is for specialty cases, google docs and the open alternatives are for everyone else. I'm about…

Google Docs isn't even in the same league as MS Office. GDocs is basically slow, web-running (I mean that as an insult), glorified Markdown editor that saves your data in an unknown format somewhere you can't access directly. About the "features average person needs" remember that users adapt their workflows to the featuers you give them and make do, not the other way around. Give them more, they'll use more.

If somebody out there has a reliable way to measure resource consumption in Windows (Mark Russinovich?), I'd be interested in a comparison between (say) a thousand word document in Word and the same document in Google Docs in Chrome.

I think you could probably add "resource hungry" to your description of GDocs....

Re: Windows Certificate Manager does not display the complete trust list

#34
post #22

One feature of Windows is defaulting to not showing messy complexity to the user. The other feature is defaulting to backward compatibility. Combined, this means that Windows often has more than two data stores for some aggregate feature [e.g. web browser security, software configuration etc.] as new versions of Windows implement these features in more robust ways. So yeah there are two or more places where certifica…

"Typical users only care about the abstraction of web security so that's what Windows surfaces." Typical users do not open certmgr.msc

People that understand what certmgr.msc does (or should do) would immediately realize that it's not telling the full story.

Re: Windows Certificate Manager does not display the complete trust list

#35
post #29

Earlier quoted context omitted.

In my experience, Docs can't even reliably align the cursor with the position between characters (problem described here[1], except my zoom is at 100% already). Thankfully all my documents have very light formatting, so I can just write in Vim and then upload them. [1] http://www.podiohelp.com/google-docs-cursor-misaligned/

I get this as well, and I have another problem. I usually work in Word but one company wants things in Google Docs. OK, I create the document in Word in Times Roman and paste it into Google Docs.... which converts it into Arial. If I copy something else from the same Word document into the same Google Doc, then Google keeps it in Times. How does that work? Is there a "smart paste" feature I've missed?

https://msdn.microsoft.com/en-us/library/windows/desktop/ms6...

Re: Windows Certificate Manager does not display the complete trust list

#36
post #33

Earlier quoted context omitted.

Google Docs isn't even in the same league as MS Office. GDocs is basically slow, web-running (I mean that as an insult), glorified Markdown editor that saves your data in an unknown format somewhere you can't access directly. About the "features average person needs" remember that users adapt their workflows to the featuers you give them and make do, not the other way around. Give them more, they'll use more.

If somebody out there has a reliable way to measure resource consumption in Windows (Mark Russinovich?), I'd be interested in a comparison between (say) a thousand word document in Word and the same document in Google Docs in Chrome. I think you could probably add "resource hungry" to your description of GDocs....

That's probably the case, but does it matter?

Re: Windows Certificate Manager does not display the complete trust list

#37

One feature of Windows is defaulting to not showing messy complexity to the user. The other feature is defaulting to backward compatibility. Combined, this means that Windows often has more than two data stores for some aggregate feature [e.g. web browser security, software configuration etc.] as new versions of Windows implement these features in more robust ways. So yeah there are two or more places where certifica…

The problem with your argument is that this is an administrative GUI that isn't even normally presented to end users unless you search for it or know how MMC snap-ins work. It is a power-user interface by all measure. And while Microsoft does simplify UIs for end users, they don't typically do the same for administrative content (just look at anything in the Admin Tools, or MMC snap-ins, no sugar coating there). Your…

Please don't call commenters "apologists" on HN.

Re: Windows Certificate Manager does not display the complete trust list

#38
post #36
post #33

Earlier quoted context omitted.

If somebody out there has a reliable way to measure resource consumption in Windows (Mark Russinovich?), I'd be interested in a comparison between (say) a thousand word document in Word and the same document in Google Docs in Chrome. I think you could probably add "resource hungry" to your description of GDocs....

That's probably the case, but does it matter?

Ask the people who spent years attacking Word for being "bloatware" ;-)

Re: Windows Certificate Manager does not display the complete trust list

#39
post #37

Earlier quoted context omitted.

The problem with your argument is that this is an administrative GUI that isn't even normally presented to end users unless you search for it or know how MMC snap-ins work. It is a power-user interface by all measure. And while Microsoft does simplify UIs for end users, they don't typically do the same for administrative content (just look at anything in the Admin Tools, or MMC snap-ins, no sugar coating there). Your…

Please don't call commenters "apologists" on HN.

It's an objective term (a defender of something controversial), unlike "linkbait" or "bashing" for example.

Re: Windows Certificate Manager does not display the complete trust list

#40
post #35
post #29

Earlier quoted context omitted.

I get this as well, and I have another problem. I usually work in Word but one company wants things in Google Docs. OK, I create the document in Word in Times Roman and paste it into Google Docs.... which converts it into Arial. If I copy something else from the same Word document into the same Google Doc, then Google keeps it in Times. How does that work? Is there a "smart paste" feature I've missed?

https://msdn.microsoft.com/en-us/library/windows/desktop/ms6...

Sorry if I'm being thick, but I'm using the same clipboard to paste between the same two documents, so I still don't see why GDocs should interpret them differently....

I can try clearing the clipboard between pastes: would that make a difference?

Post reply on HN