Earlier quoted context omitted.
There's an Amazon ISP?
https://www.amazontrust.com
The foundation of a more secure web: Google Trust Services
111–120 of 178 posts
Re: The foundation of a more secure web: Google Trust Services
#112Re: The foundation of a more secure web: Google Trust Services
#113Earlier quoted context omitted.
AOL is dead, long live AOL!/s For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.
> I don't really see Google moving to close the web parts of this. Google actively restricts which programs and extensions you can install on a Chromebook and Android, Google restricts what you can publish on their infrastructure, and AMP is also becoming somewhat of a problem. On Android, Google killed all other push notification services (and tries to prevent people from writing open source libraries for theirs), b…
Re: The foundation of a more secure web: Google Trust Services
#114I mean people don't trust Google's motives but I trust the certificate authorities less... How do we (or Google) know that the CIA and FBI can't create certificates from all the CAs because they have stolen/demanded the Root CA for them? If I was a TLA I'd want the ability to perfectly MITM anyone. I think these questions imply that there needs to be a better way to think about security and trust for web endpoints in…
> How do we (or Google) know that the CIA and FBI can't create certificates from all the CAs because they have stolen/demanded the Root CA for them? Certificate Transparency.
Might be part of the reason they are becoming their own CA.
Re: The foundation of a more secure web: Google Trust Services
#115Re: The foundation of a more secure web: Google Trust Services
#116Earlier quoted context omitted.
> I can't think of a single other example of a single-purpose CA like this. Department of Defense: http://www.disa.mil/enterprise-services/identity-and-access-...
There are numerous, Microsoft has its own subordinate CA that they operate for their own certificates. Amazon has its own root CA https://www.amazontrust.com/repository/ . There are more as well.
Re: The foundation of a more secure web: Google Trust Services
#117I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.
WoSign/StartCom got a bit of a smackdown about their stealth acquisition so there is some level of oversight.
CAs should be required to announce ownership or large administration changes, and trust in said CAs should be revoked upon change unless/until they have been re-audited.
Re: The foundation of a more secure web: Google Trust Services
#118Re: The foundation of a more secure web: Google Trust Services
#119Earlier quoted context omitted.
WoSign/StartCom got a bit of a smackdown about their stealth acquisition so there is some level of oversight.
Only because they made the mistake of sharing their infrastructure (hence, their quirks) and got caught. I wouldn't call that oversight. CAs should be required to announce ownership or large administration changes, and trust in said CAs should be revoked upon change unless/until they have been re-audited.
Re: The foundation of a more secure web: Google Trust Services
#120Earlier quoted context omitted.
Is Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.
Google isn't less trustworthy, but it is far closer to being a monopoly. I would like to bias towards a more decentralized infrastructure. Especially since Google is US based.
Simply mean used by the majority of the users?
So any sufficiently good product is monopoly, assuming that they are goodness is beyond the threshold to be favored by the majority of customers.
What do you want to say about Google's monopoly? Are Google going to hurt others and throttle effective competition? Was there any competition in CA market at all?