Earlier quoted context omitted.
I understand the rationale behind all of this, but I would get pissed off if Google sent me an email that basically says "do what we tell you to do or we will take your website offline"
That would be bad. It's not what's happening. What's happening is "update your security on the thing that you have already got security on, or else at least two of the most popular browsers will mark it as insecure; also, you will lose points in our search engine".
Distrust of Symantec TLS Certificates
121–124 of 124 posts
Re: Distrust of Symantec TLS Certificates
#122Earlier quoted context omitted.
That would be bad. It's not what's happening. What's happening is "update your security on the thing that you have already got security on, or else at least two of the most popular browsers will mark it as insecure; also, you will lose points in our search engine".
They are getting close to a monopoly in the browser market and a monopoly in the search market, so yes, this is exactly what's happening. You can pretend it's not a big deal because now they are using their power for good (I guess), but you don't know what they may do next.
That said, slippery slopes aren't usually the strongest places from which to wage an argument. We're not talking about what they might do next. We're talking about this specific instance.
Re: Distrust of Symantec TLS Certificates
#123Earlier quoted context omitted.
I would bat an eye because it's never good to rely on a single point of failure. Imagine, for instance, that at some point, LE is the only trusted CA for code-signing. If its root key gets compromised for some reason, how are we supposed to move to a new CA if the auto-updaters cannot trust the old CA anymore?
True. They should maybe consider breaking up their operation into 20 or so root certs.
Do you shard across 20 nations? If so, you have to contend with 20 intelligence agencies. It might make more sense to keep all the eggs in one basket, and have new baskets ready to go if a canary triggers.