Earlier quoted context omitted.
Exactly. I've never understood why all the US / EU language versions of Chrome, Firefox, etc. include all the root certs for CAs from China, Turkey, Russia, etc. I cannot read Mandarin or Turkish, and in the unlikely event I get forwarded to a site from a company targeting citizens from these countries, I'd prefer to just get an SSL exception instead of the 'trusted' page.
What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.
Chrome's Plan to Distrust Symantec Certificates
101–110 of 207 posts
Re: Chrome's Plan to Distrust Symantec Certificates
#102Earlier quoted context omitted.
1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…
How do you know you're not being MitM'd during step 3?
Re: Chrome's Plan to Distrust Symantec Certificates
#103Earlier quoted context omitted.
> LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? Sorry, what's a company that needs to show the company name beside the padlock? (Except maybe: Company that has too much money to spend on pointless "premium" security services without any shown benefit.)
EV is an option for companies that worry about branding - specifically ones that are well-known to do business offline. This extra layer of trust, relayed to the user from the web browser, reinforces the fact that they are on the correct website. For example, I can go grab something like "bannk.com" (notice two 'n's) and get a DV cert for it - because I hypothetically own that name. Now, I can copy the real "bank.com…
Re: Chrome's Plan to Distrust Symantec Certificates
#104Earlier quoted context omitted.
How do you know you're not being MitM'd during step 3?
For all reasonable adversary examples shy of panopticon, downloading from multiple physical sites and global proxies and comparing the same roots across downloads should be sufficient, no?
Re: Chrome's Plan to Distrust Symantec Certificates
#105I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
This is a managed by your OS. You are free to delete CA's from its trust store. What Chrome is doing is irreguarless if that cert is in your OS's store it won't trust it. Keychain for OSX mmc in windows cmd prompt Linux has /usr/share/certificates
It depends on the browser -- e.g. Chrome uses the system's CA certs, but Mozilla ships with its own.
Re: Chrome's Plan to Distrust Symantec Certificates
#106What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
https://certsimple.com It’s incredibly fast, the guy who runs it is nice, great customer service. It just does what you need.
Re: Chrome's Plan to Distrust Symantec Certificates
#107Earlier quoted context omitted.
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
>Does anyone actually look at or care about that? No. You'll note that Amazon doesn't. They spent a bunch of time trying to figure out if it made a difference for customers. It turns out it doesn't, so they don't bother with the extra expense.
I'm interested in the Amazon study if you have a link, I haven't seen that before.
(Note, I run CertSimple and we specialise in making the verification process for EV faster and much less painful, so I'm biased)
Re: Chrome's Plan to Distrust Symantec Certificates
#108Earlier quoted context omitted.
1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…
How do you know you're not being MitM'd during step 3?
Re: Chrome's Plan to Distrust Symantec Certificates
#109What are some trustable providers of EV certificates? LetsEncrypt is wonderful, but if I'm a company that needs to show the company name next to the padlock, who should I be using? What's an easy way to check if a provider (for instance Gandi, who I use for my domains) is going to be culled by this? In fact, I don't even seem to able to find certificate information in Chrome any more - clicking on the padlock just gi…
> I'm a company that needs to show the company name next to the padlock Does anyone actually look at or care about that?
Note: I'm biased. See bio.
Re: Chrome's Plan to Distrust Symantec Certificates
#110Earlier quoted context omitted.
What about the huge number of English language Chinese run ecommerce sites? Why should they be discriminated against because of their native language? That just makes the normal user who wants to buy stuff learn to ignore SSL errors.
Is it unreasonable to expect a foreign ecommerce site to use a CA that it's users can trust?
I think the @grandalf idea of selectable trust list providers has some merit (although there are some security trade-offs there).
I don't think the automatic mistrust of certificates from "CAs from China, Turkey, Russia" automatically follows from that.