Earlier quoted context omitted.
> this feels wrong, though I can't quite pin point why. It's unusual for a root CA to be run by a service that otherwise has nothing to do with CA issuance, for the primary purpose of issuing certificates for that service's first-party sites, and not for third-party sites. I can't think of a single other example of a single-purpose root CA like this. (The announcement mentions that they might use this to operate as a…
> I can't think of a single other example of a single-purpose CA like this. Department of Defense: http://www.disa.mil/enterprise-services/identity-and-access-...
The foundation of a more secure web: Google Trust Services
71–80 of 178 posts
Re: The foundation of a more secure web: Google Trust Services
#72You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.
For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.
Re: The foundation of a more secure web: Google Trust Services
#73You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.
I haven't considered the internals of the datacenter though...
Re: The foundation of a more secure web: Google Trust Services
#74Earlier quoted context omitted.
This is not in fact all that unusual at all.
I've seen many examples of non-root CAs for such purposes, but it seems unusual (though not completely unheard-of) among root CAs. I dug through Mozilla's standard certificate bundle, and found very few such certificates. Amazon has one, but they also use that to issue certificates through AWS. Someone elsewhere in the thread mentioned a DoD root CA. The certificate store has some certificates from companies like Del…
Re: The foundation of a more secure web: Google Trust Services
#75I have no love for most the major CAs I've interacted with, but this feels wrong, though I can't quite pin point why. Perhaps just a general feeling that all the internet eggs are being put, one by one, in one single alphabet basket.
If they use their browser dominance to gain the upper hand in the certificate issuance market that seems like a violation of anti-trust law.
Re: The foundation of a more secure web: Google Trust Services
#76Re: The foundation of a more secure web: Google Trust Services
#77Earlier quoted context omitted.
That's a different issue, and doesn't address what I wrote.
I think it's related? Since certificate transparency is a way of watching what's going on with all certificate providers (or at least the ones that use it), an organization that thinks Google's root is up to no good has a way of checking. It's after the fact, to be sure, but it matters for reputation.
They will already log their public certificates to CT and this will continue given their push for CT.
Re: The foundation of a more secure web: Google Trust Services
#78You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.
Re: The foundation of a more secure web: Google Trust Services
#79"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.
Is Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.
Re: The foundation of a more secure web: Google Trust Services
#80You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.
AOL is dead, long live AOL!/s For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.