Chrome's Plan to Distrust Symantec Certificates
121–130 of 207 posts
Re: Chrome's Plan to Distrust Symantec Certificates
#122I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
Re: Chrome's Plan to Distrust Symantec Certificates
#123Earlier quoted context omitted.
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
>Does anyone actually look at or care about that? No. You'll note that Amazon doesn't. They spent a bunch of time trying to figure out if it made a difference for customers. It turns out it doesn't, so they don't bother with the extra expense.
Re: Chrome's Plan to Distrust Symantec Certificates
#124What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
Re: Chrome's Plan to Distrust Symantec Certificates
#125What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
I'm unfamiliar with the problem space. What are some of the use-cases for EV certificates? It looks like lots of big name sites don't use them. Why do some companies feel they need it, while letting internet giants such as Facebook, Google, Microsoft, etc. get away without it?
Eg anyone could register "bankofanerica.com" and get a DV cert issued for it.
Only Bank of America can get a cert that shows their legal/trading company name.
Well, that's the idea. I'm not aware of any ev misissuance but I don't follow this stuff like a hawk either.
Re: Chrome's Plan to Distrust Symantec Certificates
#126Is there a list of CAs that will be affected? I can't find a link to one in the article.
Re: Chrome's Plan to Distrust Symantec Certificates
#127Re: Chrome's Plan to Distrust Symantec Certificates
#128I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…
Re: Chrome's Plan to Distrust Symantec Certificates
#129Earlier quoted context omitted.
1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…
> The user should be the one controlling the list of trusted CAs and servers, not a third party such as ad-supported company or organization distributing a web browser. No, they really shouldn't. Security is a ridiculously complex arena, and the amount of knowledge you need to make an intelligent setup on this is considerable. For tech-heads, fine, but the vast majority of people are not tech-heads. If you switched o…
1) Piss off the like, 10,000 technical nerds who care about this, by having sensible defaults. "We should really teach people to fully manage their CA chain! It sucks I have to spend 20 minutes doing this once a year after spending 10,000 hours learning how computers work."
2) Don't piss them off, but in return, get ready for user-blaming whenever someone messes up, and for your users to be 'responsible' for themselves. "If users were EDUCATED and not so stupid, they'd be able to spend 100 hours understanding the CA system and keep themselves secure!!! Not our fault if you install certificates from Brazilian hackers"
I dunno, it's mostly an observation, even if it's something of a false dichotomy, but this always seems to be the way it goes. Technical users simply have vastly different value systems. But honestly, my go-to strategy these days is mostly "whenever most technical people try to give security advice and speak on behalf of most users, almost always: do the exact opposite thing, in order to keep the users secure".
Most of us have some variant of Stockholm Syndrome to some extent.
Re: Chrome's Plan to Distrust Symantec Certificates
#130I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
As mentioned, you do have this power. But for the average user, this gives too much control, because the average user has no way to judge the trustworthiness of various CAs, if they even understood what CAs were, which they don't have the time or inclination to care about. I'd say most Hacker News readers wouldn't be able to make the correct determinations about this either.