Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

161–170 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#161
post #11
post #6

I love that you can just buy a CA and devices will trust the new owner. That’s not messed up or anything.

How could you design a system that works otherwise? Computer security is always about "this key says", not "this legal entity says".

Well you could do something like have browser vendors require a legally binding document that the ownership of a CA cannot change without notice (at which point they can reassess the CA). Not that hard actually since there are only a few browsers that matter.

Re: The foundation of a more secure web: Google Trust Services

#162
post #160
post #133

Earlier quoted context omitted.

good luck? with that attitude you deserve shitty centralized systems that spy on you. decentralization and ease of use aren't contradictory anyway. remember bit torrent? used to be very popular, even among less technical users. great UX too. click a magnet link and you have your content in a flash. the problem is that there isn't a multi-billion dollar business case for decentralized user systems. a lot of server/dc…

Spam blocking is a problem that's very difficult to solve without massive scale. Decentralized email used to suck for filtering spam because they simply didn't have the scale needed to recognize spam reliably. WordPress solved the spam issue for decentralized blog comments by centralizing it, which gives them the scale to solve it well but also gives them the ability to read probably half the blog comments on the web…

No, it really isn't. Download a copy of SpamAssassin, train it on 400 hand-picked spams from your own mailbox, train it on 400 arbitrary hams as well, and you will have very accurate spam filtering. I was shocked how well it worked; I run my own mail personally and use GMail at work, and the results are (subjectively) indistinguishable. A Dovecot plugin that keeps the Bayesian numbers up to date as I move messages in and out of the Spam and Archive (for ham) folder completes the picture.

To go deeper, it turns out that Bayesian filtering is remarkably resilient. Even attacks which try to poison your filters by including ham-like content in spams are ineffective, because spammers cannot very accurately predict what your own particular flavor of ham is like. (People don't often mail me passages from out-of-copyright Victorian romance novels.)

I find that a few botnet-reducing SMTP heuristics plus Bayesian is sufficient; I dallied with some of the fanciness that compares known-spam hashes with other people, but it turned out not to be necessary.

Re: The foundation of a more secure web: Google Trust Services

#163
post #160

Earlier quoted context omitted.

Spam blocking is a problem that's very difficult to solve without massive scale. Decentralized email used to suck for filtering spam because they simply didn't have the scale needed to recognize spam reliably. WordPress solved the spam issue for decentralized blog comments by centralizing it, which gives them the scale to solve it well but also gives them the ability to read probably half the blog comments on the web…

No, it really isn't. Download a copy of SpamAssassin, train it on 400 hand-picked spams from your own mailbox, train it on 400 arbitrary hams as well, and you will have very accurate spam filtering. I was shocked how well it worked; I run my own mail personally and use GMail at work, and the results are (subjectively) indistinguishable. A Dovecot plugin that keeps the Bayesian numbers up to date as I move messages in…

Maybe it has changed but I have vivid memories of training lots of spam a decade or so ago and still getting half-assed results. Google was the first email provider that really did a good job blocking spam.

Re: The foundation of a more secure web: Google Trust Services

#164
post #43

I don't think this is a bad thing. Instead of a third-party you trust (or rather, your user-agent trusts) vouching that Google's indeed Google, it's now Google vouching for itself, and you trust them by the virtue that they're Google. This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The reason everyone doesn't run a root CA is because it's difficult to coord…

I don't think this is a bad thing. ... This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The problem is that "connecting to a Google property" almost certainly includes their WiFi access points as well as other networking offerings. Which implies the ability to MiTM traffic encrypted from products not controlled by Google (other browsers, VPN clients, etc.).…

Google engineers have been very heavily involved in the CA/Browser Forum (https://cabforum.org), which sets issuance and trust rules for CAs. One of the things the CAB Forum is currently debating is a set of requirements mandating certificate transparency (CT) and obeying certificate authority authorization (CAA) records in DNS.

If implemented for all of these roots (and I don't see why they wouldn't, given their push on it), CT would create an open, unalterable record of every cert published from all of these roots and their subordinates. CAA, as a complement, would create a method by which you as a domain owner could control which CAs are allowed to issue certs for your domain, removing the ability to man-in-the-middle your domain without your permission.

The first step for both of these is making them mandatory for CAs (which Google is pushing hard on); once they're out there, it's possible to write plugins that will check CAA and CT records and fail closed if something looks wrong. It's a long way from perfect, but it's definitely a step in the right direction. Given Google's strong push for making those mandatory, I'm far more worried about a lot of the CAs already in my trust store than I am about these.

Re: The foundation of a more secure web: Google Trust Services

#165
post #143

Earlier quoted context omitted.

Funded mostly by you looking at Google Ads.

Nope. Funded mostly by you clicking at Google Ads. Looking is for free.

Remember they own DoubleClick, the biggest banner ad platform.

https://support.google.com/dfp_premium/answer/177222?hl=en

Re: The foundation of a more secure web: Google Trust Services

#166
post #73

Earlier quoted context omitted.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.

Google had one years ago, Google Checkout [1]. It was a PayPal competitor that was built to also provide a good API for running shopping cart experiences. Another on the list of good products that Google built, ran until they got bored with it, then closed.

[1] https://en.wikipedia.org/wiki/Google_Checkout

Re: The foundation of a more secure web: Google Trust Services

#167

Earlier quoted context omitted.

AOL is dead, long live AOL!/s For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.

We still need to make choices that guarantee it's the case in the future. We need to ensure we don't end up with environment as diverse as email where most people use Gmail, or Linux services which are all being rewritten under systemd, or many other cases where we voluntarily choose a monoculture that can force our choices in the future...

I find it disingenuous to compare Google vertically integrating the Internet with systemd, a FLOSS product that objectively solves many of problems init systems had.

Re: The foundation of a more secure web: Google Trust Services

#168
post #145

Earlier quoted context omitted.

What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.

Amazon have too far a head start on that one but it is ironic that google seem to be able to crawl and index amazon better than amazon can do internally.

It has seemed to me for quite some time that Amazon deliberately tries NOT to return what you are searching for. Oh, they'll give you one or two items that fit your search criteria, but they'll also return lots of stuff that they think you'll be interested in and possibly buy.

Re: The foundation of a more secure web: Google Trust Services

#169

Earlier quoted context omitted.

I don't think this is a bad thing. ... This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The problem is that "connecting to a Google property" almost certainly includes their WiFi access points as well as other networking offerings. Which implies the ability to MiTM traffic encrypted from products not controlled by Google (other browsers, VPN clients, etc.).…

Google engineers have been very heavily involved in the CA/Browser Forum ( https://cabforum.org ), which sets issuance and trust rules for CAs. One of the things the CAB Forum is currently debating is a set of requirements mandating certificate transparency (CT) and obeying certificate authority authorization (CAA) records in DNS. If implemented for all of these roots (and I don't see why they wouldn't, given their p…

For CAA to work, we need fully deployed DNSSEC. Not just the roots, and some resolver, but all local clients too. Otherwise, there's still weak links in the chain.

Re: The foundation of a more secure web: Google Trust Services

#170
post #152
post #29

Earlier quoted context omitted.

They have the most popular browser, mobile OS, search engine. They operate popular public DNS servers too. They add this cert and they control a vast chunk of the internet.

But there's no real lock-in effect. It's very easy to switch search engines, but rarely anyone does it because Google's simply better than Bing. If someone else comes up with better algorithms I'm sure that people would start switching. But very few people switch just to avoid the monopolist. Same for Google Chrome. Switching to another browser is a matter of a few minutes (including taking the data with you). But as…

> If someone else comes up with better algorithms I'm sure that people would start switching.

DDG has yielded results far superior to google years (IMHO, this is a bit subjective), but I don't see people moving over because google is simply "what they know".

A better alternative won't make people move, they need further motivation.

Post reply on HN