Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

91–100 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#91
post #43

I don't think this is a bad thing. Instead of a third-party you trust (or rather, your user-agent trusts) vouching that Google's indeed Google, it's now Google vouching for itself, and you trust them by the virtue that they're Google. This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The reason everyone doesn't run a root CA is because it's difficult to coord…

[deleted]

Re: The foundation of a more secure web: Google Trust Services

#93
No real problem with Google running their own CA, but can't help but to think that the same people who provide the browser, the search engine and the OS, now also provide the certificates on who and what to trust.

As much as we might trust Google, shouldn't there be something like separation of powers as a safeguard?

Re: The foundation of a more secure web: Google Trust Services

#94
post #65

You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.

so like Amazon.

There's an Amazon ISP?

Re: The foundation of a more secure web: Google Trust Services

#95
post #3

I have no love for most the major CAs I've interacted with, but this feels wrong, though I can't quite pin point why. Perhaps just a general feeling that all the internet eggs are being put, one by one, in one single alphabet basket.

They control a popular public dns server, a CA, a global local cache, and control over the most popular browser and phone. They have all the pieces to do almost seamless MITM.

"We see you haven't signed up yet for AMP, so we've done the work for you"

Yes, I get they wouldn't do this, but the fact that they could is a little scary.

Re: The foundation of a more secure web: Google Trust Services

#96
post #87
post #73

Earlier quoted context omitted.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

Go poke around: https://research.google.com/pubs/papers.html You will see lots of custom stuff that Google does. There are many things that are better to outsource to 3rd parties, but many things are better in-house because the solutions just don't exist or they cost too much for the volume they need. Some examples: Network routers for CLOS topology (there are pictures of some of the hardware): https://research.googl…

Interesting stuff. I've heard about the TPU chip but not the rest.

They're still eons away from e.g. Intel or Samsung when it comes to vertical integration on the hardware side.

I believe that Samsung is the only company in the world that is capable of building an entire computer (e.g., laptop or smartphone) from scratch completely in-house. They can design software and OSes AND manufacture SoCs, memory, LED panels, etc. It's very impressive.

Re: The foundation of a more secure web: Google Trust Services

#97
post #65

You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.

AOL is dead, long live AOL!/s For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.

> I don't really see Google moving to close the web parts of this.

Google actively restricts which programs and extensions you can install on a Chromebook and Android, Google restricts what you can publish on their infrastructure, and AMP is also becoming somewhat of a problem.

On Android, Google killed all other push notification services (and tries to prevent people from writing open source libraries for theirs), by only allowing notifications from Google Cloud Messaging to work when the device is saving battery (basically always on recent versions).

After trying to fight this for quite a while, I do really see Google moving to close this.

Re: The foundation of a more secure web: Google Trust Services

#99

Hmm, I wonder if Alphabet will spin up a made at Google alternative to Let's Encrypt?

Disclosure: I am the author of that post and Product Manager for this project as well as other related work like Certificate Transparency and Key Transparency.

While I can not say what Google will do in the future, I can say we are very supportive of Let's Encrypt. We have provided them funding and I personally act as an advisor to Let's Encrypt.

In short, we love what Let's Encrypt is doing.

Re: The foundation of a more secure web: Google Trust Services

#100
post #96
post #87

Earlier quoted context omitted.

Go poke around: https://research.google.com/pubs/papers.html You will see lots of custom stuff that Google does. There are many things that are better to outsource to 3rd parties, but many things are better in-house because the solutions just don't exist or they cost too much for the volume they need. Some examples: Network routers for CLOS topology (there are pictures of some of the hardware): https://research.googl…

Interesting stuff. I've heard about the TPU chip but not the rest. They're still eons away from e.g. Intel or Samsung when it comes to vertical integration on the hardware side. I believe that Samsung is the only company in the world that is capable of building an entire computer (e.g., laptop or smartphone) from scratch completely in-house. They can design software and OSes AND manufacture SoCs, memory, LED panels,…

On that note it would be really interesting to see the percentage breakdown of who's IP made your phone/laptop/etc
Post reply on HN