Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

121–130 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#121

Earlier quoted context omitted.

AOL is dead, long live AOL!/s For serious though, there's not really any lock-in here (yet). You could replace everything from the certificate through the public DNS with GoDaddy and things would work just fine. I don't really see Google moving to close the web parts of this.

We still need to make choices that guarantee it's the case in the future. We need to ensure we don't end up with environment as diverse as email where most people use Gmail, or Linux services which are all being rewritten under systemd, or many other cases where we voluntarily choose a monoculture that can force our choices in the future...

> We need to ensure we don't end up with environment as diverse as email where most people use Gmail

Good luck making something that's both 1) the most convenient and 2) not centralized.

Re: The foundation of a more secure web: Google Trust Services

#122

No real problem with Google running their own CA, but can't help but to think that the same people who provide the browser, the search engine and the OS, now also provide the certificates on who and what to trust. As much as we might trust Google, shouldn't there be something like separation of powers as a safeguard?

There is: they are intertwined with other regimes:

  * The international banking regime
  * The US legal regime for corporate purposes
  * Many other national regimes for operating purposes

Re: The foundation of a more secure web: Google Trust Services

#123
post #57

Earlier quoted context omitted.

Is Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.

I didn't make a claim if they were trustworthy. Google has leveraged their properties to force people to trust them with the rest of the internet, regardless of if you think they are trustworthy or not.

"Google has leveraged their properties to force people to trust them with the rest of the internet"

Google saw the dismal situation of Internet CA, and forces internet to move to a better situation. Forcing people behave better is a good thing, IMHO. If you think other way around, there will not be a common ground for discussion between you and me.

Re: The foundation of a more secure web: Google Trust Services

#124
post #60

Earlier quoted context omitted.

Google isn't less trustworthy, but it is far closer to being a monopoly. I would like to bias towards a more decentralized infrastructure. Especially since Google is US based.

What do you mean by 'monopoly'? Simply mean used by the majority of the users? So any sufficiently good product is monopoly, assuming that they are goodness is beyond the threshold to be favored by the majority of customers. What do you want to say about Google's monopoly? Are Google going to hurt others and throttle effective competition? Was there any competition in CA market at all?

Regardless of your personal opinion, the law and the historical record state otherwise.

To answer your later questions:

Too many essential services under one umbrella.

Not quite.

It's competition stifling.

Yes.

Yes.

Re: The foundation of a more secure web: Google Trust Services

#125

Earlier quoted context omitted.

> this feels wrong, though I can't quite pin point why. It's unusual for a root CA to be run by a service that otherwise has nothing to do with CA issuance, for the primary purpose of issuing certificates for that service's first-party sites, and not for third-party sites. I can't think of a single other example of a single-purpose root CA like this. (The announcement mentions that they might use this to operate as a…

I guess if NSA/FBI forces google to hand over the CA keys, they kan orchestrate undetectable MITM-attacks. I wonder why browser won't automatically store the fingerprint for every HTTPS-certificate it encounters and throw up a fuzz to the user if a certificate changes without any good reason?

Perspectives for Firefox does this. But Google rotates their certs, this effectively disabling the approach and forcing most users to trust anything 'Google'.

Re: The foundation of a more secure web: Google Trust Services

#127
post #43

I don't think this is a bad thing. Instead of a third-party you trust (or rather, your user-agent trusts) vouching that Google's indeed Google, it's now Google vouching for itself, and you trust them by the virtue that they're Google. This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The reason everyone doesn't run a root CA is because it's difficult to coord…

  I don't think this is a bad thing. ... This ought
  not be surprising: presumably, who better to say
  that Google is indeed Google than Google itself?
The problem is that "connecting to a Google property" almost certainly includes their WiFi access points as well as other networking offerings. Which implies the ability to MiTM traffic encrypted from products not controlled by Google (other browsers, VPN clients, etc.).

As stated in this Stackoverflow response[0]:

  Especially #2 is rather nasty, even if you
  pay for a highly trusted certificate, your site
  will not be in any way locked to that
  certificate, you have to trust all CAs in the
  client's browser since any of them can generate
  a fake cert for your site that is just as valid.
  It also does not require access to either the
  server or the client.
I wouldn't be surprised if AMP is also in play for this type of MiTM, but do not know for certain. Android native apps, however, are definitely poised to be compromised.

0 - http://stackoverflow.com/a/14907718

Re: The foundation of a more secure web: Google Trust Services

#128
post #73
post #65

You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.

Re: The foundation of a more secure web: Google Trust Services

#129
post #73

Earlier quoted context omitted.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.

What? There's a big "shopping" tab at the top of every search results page.

Re: The foundation of a more secure web: Google Trust Services

#130
post #99

Hmm, I wonder if Alphabet will spin up a made at Google alternative to Let's Encrypt?

Disclosure: I am the author of that post and Product Manager for this project as well as other related work like Certificate Transparency and Key Transparency. While I can not say what Google will do in the future, I can say we are very supportive of Let's Encrypt. We have provided them funding and I personally act as an advisor to Let's Encrypt. In short, we love what Let's Encrypt is doing.

I do too, and I also think that if one reasonably well funded, free CA that has full transparency is great, then two would be awesome :D
Post reply on HN