Live data from Hacker News

Changes to Trusted Certificate Authorities in Android Nougat

android-developers.blogspot.com

101–103 of 103 posts

Re: Changes to Trusted Certificate Authorities in Android Nougat

#101
post #73
post #40

Taking away the user's ability to manage their own security should bring with it the responsibility - and liability - for any problems that derive from the imposed settings. The paternalistic attitude that users are and always will be ignorant is not only offensive. it is counterproductive. Security is not a product, and keeping people ignorant of the trust models they are relying on is a recipe for disaster in the l…

I very much agree with the liability responsibility and liability argument that you're raising. I also fully believe self-driving car makers should be 100% responsible for accidents and hacking incidents of their cars and they should fully compensate the victims of such accidents and hacks. However, I think this is generally a good thing. When Android has 50 different OEMs (or whatever the number is), then some stand…

> This policy would prevent all of those things. That doesn't mean we still won't see CNNIC and Blue Coat/Symantec and other untrustworthy certificates loaded up by default in all Android devices (which you can still disable yourself), but I think overall this is still a good move from Google.

I'm ok with this. Even if I can't add a custom root certificate, I would like the ability to distrust any root certificate I explicitly do not like. That coupled with standardization of certificates loaded by default makes this sound like a welcome change.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#102
post #40

Taking away the user's ability to manage their own security should bring with it the responsibility - and liability - for any problems that derive from the imposed settings. The paternalistic attitude that users are and always will be ignorant is not only offensive. it is counterproductive. Security is not a product, and keeping people ignorant of the trust models they are relying on is a recipe for disaster in the l…

you can always compile your own version of android that does not do this...

Re: Changes to Trusted Certificate Authorities in Android Nougat

#103
post #85

Earlier quoted context omitted.

Data loss prevention refers to preventing unauthorized, purposeful or unintentional, access or transmission of sensitive or critical information. A comprehensive DLP solution covers data at rest, data in use and data in motion. Network DLP solutions help address the data in motion. They use MITMing in order to inspect data leaving the enterprise. They are often deployed in order to meet regulatory data protection req…

> unauthorized, purposeful or unintentional, access or transmission of sensitive or critical information So there's no loss of data involved. You still have all the data you had before.

I can't tell if you're being deliberate obtuse or just trolling...

Data loss is an accepted term to describe what tssva is talking about - and yes, it is a real thing in the real world - e.g.:

https://en.wikipedia.org/wiki/Data_loss_prevention_software

For example, I used to work in investment banking. It was well known, and expected, that us (and probably most other institutions) had network level monitoring, to prevent say, the leaking of a deal on some chat or web forum somewhere. Believe me, when there's lots of money involved, there are plenty of incentives to leak things.

You'd look pretty silly if you had to explain to the regulatory authorities that you took zero steps to secure your network perimeter, or prevent the exfiltration of privileged or confidential data.

And there are other legitimate use cases - educational institutions and schools come to mind.

Post reply on HN