Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

171–178 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#173

No real problem with Google running their own CA, but can't help but to think that the same people who provide the browser, the search engine and the OS, now also provide the certificates on who and what to trust. As much as we might trust Google, shouldn't there be something like separation of powers as a safeguard?

You trust the hw vendor, the os vendor and the browser vendor - and you trust the CA. Google already had two out of four in many cases. You're not safe from the OS vendor by using a different browser, or CA.

Re: The foundation of a more secure web: Google Trust Services

#174
I’ve been ripped off 4 times already, thankfully my friend gave me a reliable contact, he works with discretion and delivers now i want you to look no further for a better hacker because the best is here.. EAGLEEYEHACK56 @ GMAIL . COM is good in every hacking way, does from Facebook,email,Instagram,twitter,snapchat,, change grades/increase GPA ,bank transfer, blank ATM card. HACK BITCOIN, VERIFIED PAYPAL ACCOUNT, PM ACCOUNT, GIFT CARDS, FULLZ, E.T.C You just name it. I have worked with him so many times i can boast of his work. Thank you so much EAGLEEYEHACK

Re: The foundation of a more secure web: Google Trust Services

#175
post #73
post #65

You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

I’ve been ripped off 4 times already, thankfully my friend gave me a reliable contact, he works with discretion and delivers now i want you to look no further for a better hacker because the best is here.. EAGLEEYEHACK56 @ GMAIL . COM is good in every hacking way, does from Facebook,email,Instagram,twitter,snapchat,, change grades/increase GPA ,bank transfer, blank ATM card. HACK BITCOIN, VERIFIED PAYPAL ACCOUNT, PM ACCOUNT, GIFT CARDS, FULLZ, E.T.C You just name it. I have worked with him so many times i can boast of his work. Thank you so much EAGLEEYEHACK

Re: The foundation of a more secure web: Google Trust Services

#176
post #163

Earlier quoted context omitted.

No, it really isn't. Download a copy of SpamAssassin, train it on 400 hand-picked spams from your own mailbox, train it on 400 arbitrary hams as well, and you will have very accurate spam filtering. I was shocked how well it worked; I run my own mail personally and use GMail at work, and the results are (subjectively) indistinguishable. A Dovecot plugin that keeps the Bayesian numbers up to date as I move messages in…

Maybe it has changed but I have vivid memories of training lots of spam a decade or so ago and still getting half-assed results. Google was the first email provider that really did a good job blocking spam.

There is one setting, underdocumented, which makes a big difference these days. spamc has a default ceiling of 10K, messages larger than which it passes unchecked. Spammers have started routinely including images just over that threshold to defeat default installs. Bump that up a bit, and your accuracy will go way up.

Re: The foundation of a more secure web: Google Trust Services

#177
post #151

Earlier quoted context omitted.

To clarify, that's a CA, not an ISP

But as Google wants to stop the Fiber project, they will also stop being one. Apparently being an ISP adds no value to the rest.

I wonder, with Alphabet's investment in SpaceX, if they see satilite as the future instead of fiber.

Re: The foundation of a more secure web: Google Trust Services

#178

Earlier quoted context omitted.

I don't think this is a bad thing. ... This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The problem is that "connecting to a Google property" almost certainly includes their WiFi access points as well as other networking offerings. Which implies the ability to MiTM traffic encrypted from products not controlled by Google (other browsers, VPN clients, etc.).…

Google engineers have been very heavily involved in the CA/Browser Forum ( https://cabforum.org ), which sets issuance and trust rules for CAs. One of the things the CAB Forum is currently debating is a set of requirements mandating certificate transparency (CT) and obeying certificate authority authorization (CAA) records in DNS. If implemented for all of these roots (and I don't see why they wouldn't, given their p…

According to here[0], when you say:

  CT would create an open, unalterable record of
  every cert published from all of these roots
  and their subordinates.
That provides no substantiation for Google's push to be a Certificate Authority (CA). It arguably makes a case for Google to be a "Log Server" (which has its own troubling implications as that could then (now?) hook Google into the verification process of every certificate issued[1]). But absolutely nothing about CT needs/implies/warrants Google to become a CA.

  Given Google's strong push for making those
  mandatory, I'm far more worried about a lot
  of the CAs already in my trust store than I
  am about these.
The very authority to which you are appealing is precisely the one which is suspect.

0 - https://www.certificate-transparency.org/how-ct-works

1 - From [0]:

  During the TLS handshake, the TLS client receives
  the SSL certificate and the certificate’s SCT.
  As usual, the TLS client validates the certificate
  and its signature chain. In addition, the TLS
  client validates the log’s signature on the SCT ...
Post reply on HN