I have no love for most the major CAs I've interacted with, but this feels wrong, though I can't quite pin point why. Perhaps just a general feeling that all the internet eggs are being put, one by one, in one single alphabet basket.
They control a popular public dns server, a CA, a global local cache, and control over the most popular browser and phone. They have all the pieces to do almost seamless MITM. "We see you haven't signed up yet for AMP, so we've done the work for you" Yes, I get they wouldn't do this, but the fact that they could is a little scary.
The foundation of a more secure web: Google Trust Services
131–140 of 178 posts
Re: The foundation of a more secure web: Google Trust Services
#132but then again, government players plague every security system we have.
Re: The foundation of a more secure web: Google Trust Services
#133Earlier quoted context omitted.
We still need to make choices that guarantee it's the case in the future. We need to ensure we don't end up with environment as diverse as email where most people use Gmail, or Linux services which are all being rewritten under systemd, or many other cases where we voluntarily choose a monoculture that can force our choices in the future...
> We need to ensure we don't end up with environment as diverse as email where most people use Gmail Good luck making something that's both 1) the most convenient and 2) not centralized.
the problem is that there isn't a multi-billion dollar business case for decentralized user systems. a lot of server/dc tech is both decentralized and distributed because it is a more robust architecture. again, the reason this doesn't extend to the consumer is because it give them too much control and clogs up the revenue stream.
this isn't a technical or usability problem, as you claim. this is 100% economic.
Re: The foundation of a more secure web: Google Trust Services
#134Earlier quoted context omitted.
I guess if NSA/FBI forces google to hand over the CA keys, they kan orchestrate undetectable MITM-attacks. I wonder why browser won't automatically store the fingerprint for every HTTPS-certificate it encounters and throw up a fuzz to the user if a certificate changes without any good reason?
It's opt-in by the site, but that's what public key pinning is: https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning
Re: The foundation of a more secure web: Google Trust Services
#135Earlier quoted context omitted.
I guess if NSA/FBI forces google to hand over the CA keys, they kan orchestrate undetectable MITM-attacks. I wonder why browser won't automatically store the fingerprint for every HTTPS-certificate it encounters and throw up a fuzz to the user if a certificate changes without any good reason?
Because the browser (or the user) has no way of knowing if the certificate changed for a good reason. Certificate pinning tries to tackle this at the CA level but it's not perfect (in a nutshell, browsers know that google.com can be signed only by a certain small subset of CAs).
The certificate pinning of CA is not that useful.
So google rotate a lot of certs, but I bet 95% of the internet use one cert for one server until it expires. Google could fall in in line.
Re: The foundation of a more secure web: Google Trust Services
#136Re: The foundation of a more secure web: Google Trust Services
#137In the meantime, DNSCurve would be a great start, vs the major issues I have found with DNSSec.
Re: The foundation of a more secure web: Google Trust Services
#138Earlier quoted context omitted.
Most of us adjudicate too much value to TLDs. It's an artificially scarce resource and most people here learned about the Internet when these TLDs were even scarcer.
Well, personally I think that most of us adjudicate too little value to TLDs. The point of DNS is to be hierarchical instead of one flat space, so imho all legacy TLDs should have been immediately deprecated the day ccTLDs were introduced, and countries should have been endorsed to maintain second level hierarchy (somewhat like .uk had for some time). But of course that train left the station 30 years ago... in the c…
Re: The foundation of a more secure web: Google Trust Services
#139Earlier quoted context omitted.
What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.
What? There's a big "shopping" tab at the top of every search results page.
Re: The foundation of a more secure web: Google Trust Services
#140You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.