Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

111–120 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#112
post #34

All I can say is this - what if I don't trust Google one iota?

Remove the Google root certificates from your system once they deploy them.

and don't visit any Google sites, which are the only ones deploying Google certificates.

Re: The foundation of a more secure web: Google Trust Services

#113
post #97

Earlier quoted context omitted.

AOL is dead, long live AOL!/s For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.

> I don't really see Google moving to close the web parts of this. Google actively restricts which programs and extensions you can install on a Chromebook and Android, Google restricts what you can publish on their infrastructure, and AMP is also becoming somewhat of a problem. On Android, Google killed all other push notification services (and tries to prevent people from writing open source libraries for theirs), b…

[deleted]

Re: The foundation of a more secure web: Google Trust Services

#114
post #83

I mean people don't trust Google's motives but I trust the certificate authorities less... How do we (or Google) know that the CIA and FBI can't create certificates from all the CAs because they have stolen/demanded the Root CA for them? If I was a TLA I'd want the ability to perfectly MITM anyone. I think these questions imply that there needs to be a better way to think about security and trust for web endpoints in…

> How do we (or Google) know that the CIA and FBI can't create certificates from all the CAs because they have stolen/demanded the Root CA for them? Certificate Transparency.

Which is why Google knew that someone issues a cert for their website: https://security.googleblog.com/2015/09/improved-digital-cer...

Might be part of the reason they are becoming their own CA.

Re: The foundation of a more secure web: Google Trust Services

#116
post #71

Earlier quoted context omitted.

> I can't think of a single other example of a single-purpose CA like this. Department of Defense: http://www.disa.mil/enterprise-services/identity-and-access-...

There are numerous, Microsoft has its own subordinate CA that they operate for their own certificates. Amazon has its own root CA https://www.amazontrust.com/repository/ . There are more as well.

Amazon is using their CA for issuing customer ELB/Cloudfront certificates, not just their own stuff, and not even all of it: the cert I see at https://amazon.com's is Symantec-issued.

Re: The foundation of a more secure web: Google Trust Services

#117
post #12
post #6

I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.

WoSign/StartCom got a bit of a smackdown about their stealth acquisition so there is some level of oversight.

Only because they made the mistake of sharing their infrastructure (hence, their quirks) and got caught. I wouldn't call that oversight.

CAs should be required to announce ownership or large administration changes, and trust in said CAs should be revoked upon change unless/until they have been re-audited.

Re: The foundation of a more secure web: Google Trust Services

#118
post #86
post #57

Earlier quoted context omitted.

Is Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.

FWIW, I think Google is less trustworthy than the HK Post Office.

Why?

Re: The foundation of a more secure web: Google Trust Services

#119
post #12

Earlier quoted context omitted.

WoSign/StartCom got a bit of a smackdown about their stealth acquisition so there is some level of oversight.

Only because they made the mistake of sharing their infrastructure (hence, their quirks) and got caught. I wouldn't call that oversight. CAs should be required to announce ownership or large administration changes, and trust in said CAs should be revoked upon change unless/until they have been re-audited.

That is effectively how both the Mozilla and Microsoft programs root store programs works.

Re: The foundation of a more secure web: Google Trust Services

#120
post #60
post #57

Earlier quoted context omitted.

Is Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.

Google isn't less trustworthy, but it is far closer to being a monopoly. I would like to bias towards a more decentralized infrastructure. Especially since Google is US based.

What do you mean by 'monopoly'?

Simply mean used by the majority of the users?

So any sufficiently good product is monopoly, assuming that they are goodness is beyond the threshold to be favored by the majority of customers.

What do you want to say about Google's monopoly? Are Google going to hurt others and throttle effective competition? Was there any competition in CA market at all?

Post reply on HN