I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.
The foundation of a more secure web: Google Trust Services
11–20 of 178 posts
Re: The foundation of a more secure web: Google Trust Services
#12I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.
Re: The foundation of a more secure web: Google Trust Services
#13"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.
It's disgusting but pretty much corporate life 101.
Re: The foundation of a more secure web: Google Trust Services
#14"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.
You may want to look into certificate transparency and who's supporting it.
Re: The foundation of a more secure web: Google Trust Services
#15Re: The foundation of a more secure web: Google Trust Services
#16I think SSL certificates need to be replaced. Security can NOT be designed with the 'good guy' in mind. if it can be broken at all we need an alternative.
The certificates are OK. The issue is the way they are signed and distributed. Lots of issues with the current PK infrastructure is limited by the certificate transparency.
Re: The foundation of a more secure web: Google Trust Services
#17Earlier quoted context omitted.
You may want to look into certificate transparency and who's supporting it.
That's a different issue, and doesn't address what I wrote.
Re: The foundation of a more secure web: Google Trust Services
#18I think SSL certificates need to be replaced. Security can NOT be designed with the 'good guy' in mind. if it can be broken at all we need an alternative.
The certificates are OK. The issue is the way they are signed and distributed. Lots of issues with the current PK infrastructure is limited by the certificate transparency.
I think an encryption solutions that cannot be 'broken' for decryption is far more required than one that has the 'good guy' in mind. I do not find it an acceptable solution for critical data.
Re: The foundation of a more secure web: Google Trust Services
#19Earlier quoted context omitted.
You may want to look into certificate transparency and who's supporting it.
That's a different issue, and doesn't address what I wrote.
It's after the fact, to be sure, but it matters for reputation.
Re: The foundation of a more secure web: Google Trust Services
#20Earlier quoted context omitted.
The certificates are OK. The issue is the way they are signed and distributed. Lots of issues with the current PK infrastructure is limited by the certificate transparency.
it is too hard for me to believe that root ca's have not been compromised when anyone working at these companies could likely easily take it without anyone noticing. I do not think transparency has anything at all to do with it. I think an encryption solutions that cannot be 'broken' for decryption is far more required than one that has the 'good guy' in mind. I do not find it an acceptable solution for critical data…