Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

1–10 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#4
"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates."

The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.

Re: The foundation of a more secure web: Google Trust Services

#5

I think SSL certificates need to be replaced. Security can NOT be designed with the 'good guy' in mind. if it can be broken at all we need an alternative.

The certificates are OK. The issue is the way they are signed and distributed.

Lots of issues with the current PK infrastructure is limited by the certificate transparency.

Re: The foundation of a more secure web: Google Trust Services

#7
post #4

"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.

You may want to look into certificate transparency and who's supporting it.

Re: The foundation of a more secure web: Google Trust Services

#8
post #4

"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.

[deleted]

Re: The foundation of a more secure web: Google Trust Services

#9
post #3

I have no love for most the major CAs I've interacted with, but this feels wrong, though I can't quite pin point why. Perhaps just a general feeling that all the internet eggs are being put, one by one, in one single alphabet basket.

Let's hope they stick to publishing all certificates into the certificate transparency list (Merkle tree).

Re: The foundation of a more secure web: Google Trust Services

#10
post #4

"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.

[deleted]
Post reply on HN