Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

141–150 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#141
Slightly offtopic but still related to web-security in general; how can I be sure about chrome extensions that I'm using are not doing malicious stuff? I think if a state actor or a resourceful entity wishes to steal data of users, attacking/hijacking/buying a popular chrome extension would be so much easier than attacking a CA or doing MITM over SSL, and trying to decrypt it.

I've always hated the concept of certain chrome extensions having full access to all the pages I visit in the browser but sometimes its necessary. Ad blockers are way too high on the list of potential attack targets, close second would be web development extensions like editthiscookie.

There needs to be a way for webpages to indicate that they don't want any external scripts running on the page. Even a setting in chrome would be really helpful. I don't want external scripts to be running on my bank website, or when I'm working with my stock exchange website. Right now I'm making do with multiple chrome profiles but that doesn't cut it. There needs to be some initiative in this regard from major browser vendors.

Re: Chrome's Plan to Distrust Symantec Certificates

#142

Slightly offtopic but still related to web-security in general; how can I be sure about chrome extensions that I'm using are not doing malicious stuff? I think if a state actor or a resourceful entity wishes to steal data of users, attacking/hijacking/buying a popular chrome extension would be so much easier than attacking a CA or doing MITM over SSL, and trying to decrypt it. I've always hated the concept of certain…

Yes, I agree. The possibility of a rogue extension stealing data also freaks me out. All you need is the Google account of 1 popular extension's author to be hijacked, and now the person has full control over all the credentials of every user of that extension within an hour or so.

I was so concerned about this potentially ticking time bomb, in fact, that I sent an email about this to a prominent person on Chrome's security team many months ago.

I did not receive a reply.

Re: Chrome's Plan to Distrust Symantec Certificates

#143

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

This is a managed by your OS. You are free to delete CA's from its trust store. What Chrome is doing is irreguarless if that cert is in your OS's store it won't trust it. Keychain for OSX mmc in windows cmd prompt Linux has /usr/share/certificates

Firefox has it's own certificate bundle, so do Java applications.

Re: Chrome's Plan to Distrust Symantec Certificates

#144

Slightly offtopic but still related to web-security in general; how can I be sure about chrome extensions that I'm using are not doing malicious stuff? I think if a state actor or a resourceful entity wishes to steal data of users, attacking/hijacking/buying a popular chrome extension would be so much easier than attacking a CA or doing MITM over SSL, and trying to decrypt it. I've always hated the concept of certain…

For web pages to indicate? No, that'll get attached to every terrible ad in the world.

Re: Chrome's Plan to Distrust Symantec Certificates

#145

Earlier quoted context omitted.

1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…

While I do think blind trust has serious flaws, I do believe that having "trustworthy enough defaults" is good enough for the average user while making it relatively simple to overwrite those defaults would be nice.

Right now there is a big gap between "trustworthy enough defaults" and "security expert who has the judgment to determine which CAs deserve to be trusted with the most sensitive data".

It's easy enough to remove CAs for one's self, the issue is understanding the possible entanglements that might make some of them less trustworthy or more easily compromised. That requires quite a bit of expertise and judgment.

Re: Chrome's Plan to Distrust Symantec Certificates

#146

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…

Browsers are primarily in the user fingerprinting business, but I would not be surprised that there is absolutely no incentive nor desire to invest in "security and privacy"(tm) other than to facilitate their main purpose. Let me stress this once again, the main purpose of a modern browser is to enable global, cross-network user tracking so that companies like google can collect data regardless of whether you "accept cookies", use vpns or sign up into one of google apps(which makes that "see what data google has about you" project even more evil).

Re: Chrome's Plan to Distrust Symantec Certificates

#147

Earlier quoted context omitted.

As mentioned, you do have this power. But for the average user, this gives too much control, because the average user has no way to judge the trustworthiness of various CAs, if they even understood what CAs were, which they don't have the time or inclination to care about. I'd say most Hacker News readers wouldn't be able to make the correct determinations about this either.

It's also worth noting that for average users, whenever any sort of "option" is given that can potentially open a security whole, there exists some malware out there that tries to get the user to abuse that option in order to infect them. This always happens, and is the reason so many things on Chrome are locked down and very hard to modify.

I e­a­r­n $­8­5 h­ou­rl­y f­or w­­or­­ki­­ng on­­lin­­e fr­om ho­­­m­e. I n­ev­­er th­o­ug­ht t­ha­t i­t­'­s po­ss­ibl­­e bu­t m­­­y ­be­st f­r­ie­nd­ i­s ma­­­ki­ng ­$­­1­00­0­­0 ev­­­­e­ry mo­­­n­­th wo­­r­­k­­ing t­h­is jo­­b a­­nd sh­­­e to­­l­­d m­­­e ab­­o­­ut it. Ch­­ec­­­­k it o­ut b­­y v­­is­it­in­­­g fo­­l­­lo­­­wi­­n li­­­n­­k>> AMAZING JOBS

ᴵᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­ᴵ­­w­w­w.b­o­s­s­c­y­b­e­r.c­o­mᴵᴵᴵᴵᴵᴵᴵᴵ

Re: Chrome's Plan to Distrust Symantec Certificates

#148

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…

And how would one know which certs to include? Seriously, I've been trying to solve that issue for years.

Discussion on Super User (Stack Exchange): https://superuser.com/questions/818065/how-to-know-which-cer...

Re: Chrome's Plan to Distrust Symantec Certificates

#149

Slightly offtopic but still related to web-security in general; how can I be sure about chrome extensions that I'm using are not doing malicious stuff? I think if a state actor or a resourceful entity wishes to steal data of users, attacking/hijacking/buying a popular chrome extension would be so much easier than attacking a CA or doing MITM over SSL, and trying to decrypt it. I've always hated the concept of certain…

Chrome has a good permissions model that i don't think can be much improved on. An ad-blocker needs access to data on every page you visit in order to do its job. I don't really see a way around it; Thats just how the web is constructed.. You can disable 3rd party scripts on your side (Firefox has Noscript addon for that; chrome should have something similar) but that may break the website you 're visiting

Workarounds : Disable add-ons in incognito mode, and conduct your important business there..

Or use a second chrome profile with no extensions for confidential stuff..

Re: Chrome's Plan to Distrust Symantec Certificates

#150
post #119

Earlier quoted context omitted.

I believe that EV certificates cannot be wildcard certs, is this still true?

Yep, what @detaro said. Here's the specifics: https://certsimple.com/blog/wildcard-ev-certificate

Like the site, but the example seems off.

It talks about 'bankofamerica.com.fraud.ru' in the first paragraph, but then discusses how 'fraud.ph' (why did we change TLDs? This should stick to ru or the above should be changed to ph) gets a wildcard cert for '* .com.fraud.com' (we changed TLDs again, to com this time. I assume we're talking about 'fraud.ph' getting a cert for * .com.fraud.ph - or .. we stick with ru)

Post reply on HN