Live data from Hacker News

Chrome's Plan to Distrust Symantec Certificates

security.googleblog.com

131–140 of 207 posts

Re: Chrome's Plan to Distrust Symantec Certificates

#131

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…

If the system by default without users doing anything said common popular websites were insecure, most users would just learn to click through (no matter how many clicks it took) and generally ignore all security warnings. It's crying wolf. You would have actually decreased overall security.

(Or they'd just switch to a different browser without these problems).

I understand the intent of your suggestion, and you're not wrong in an ideal world, but mass-market security needs to take actual human psychology of non-technical users into account too.

Re: Chrome's Plan to Distrust Symantec Certificates

#132
post #118

Earlier quoted context omitted.

Is it unreasonable to expect a foreign ecommerce site to use a CA that it's users can trust?

You're right. Americans should discard Turkish and Chinese CAs in favour of one homed in the heart of their tech capital in Silicon Valley. Clearly those foreign ones are shysters and not to be trusted like a locally-built, trustworthy business! Oh, what's that? Symantec is an American company, headquartered in Mountain View, CA?

Meanwhile, the rest of the world probably wonders if they should trust American CA's!

I'm not sure a geographically silo'd internet is what we should be going for. i miss the days when the dream of the internet was prefiguring a borderless world.

Re: Chrome's Plan to Distrust Symantec Certificates

#133
post #42

Earlier quoted context omitted.

i remember needing a util for this: https://support.norton.com/sp/en/us/home/current/solutions/v... was a key component of my debloating efforts back in the XP days.

Norton protect quietly reinstalled itself after I ran that tool. Oracle snuck it onto my system in a java update and I ended up having to dig through the registry and disk to weed it out. It is malware, plain and simple.

What could the lifetime value of a Norton customer be that they went to such incredible lengths to aquire?

Re: Chrome's Plan to Distrust Symantec Certificates

#134
post #112
post #111

Earlier quoted context omitted.

Wouldn't you say it would be enough to pin those certs to TLDs?

By TLD do you mean country domains? Then absolutely not. Why should a US company not be allowed to use a Swiss-issued certificate for a .io domain name?

And for that matter -- if a CA really is untrustworthy, why should domains under any TLD be exposed to them?

Re: Chrome's Plan to Distrust Symantec Certificates

#135
post #93

Earlier quoted context omitted.

>Does anyone actually look at or care about that? No. You'll note that Amazon doesn't. They spent a bunch of time trying to figure out if it made a difference for customers. It turns out it doesn't, so they don't bother with the extra expense.

For someone as big as Amazon, isn't it cheaper to just get an EV cert than spending significant time figuring out whether it's worth it?

Not if it increases conversation rate by X%.

Re: Chrome's Plan to Distrust Symantec Certificates

#136
post #91
post #66

Earlier quoted context omitted.

See here [1] for a pretty good write-up arguing EV isn't worth much. One issue is that it only has value if you would notice it is missing. Would you trust a paypal site that just had the green padlock, but not the name? Do you think your parents would? [1] https://www.troyhunt.com/journey-to-an-extended-validation-c...

We need an 'Expect-EV' header, just like 'Expect-CT'. Or maybe all websites that request certain info (like SSN or credit card) should be required to have EV. EV is more expensive and onerous but it has the potential to thwart phishing.

> We need an 'Expect-EV' header, just like 'Expect-CT'.

What good would that header do? A phishing site (say, "paypaaaaal.com") would simply not set it.

> Or maybe all websites that request certain info (like SSN or credit card) should be required to have EV.

EV certificates are not available to everyone. In particular, they're only available to users in certain countries, and even then only to registered businesses.

Besides, how do you enforce a requirement like that, short of barring users from submitting data that looks like a credit card to a site without an EV certificate? (Which would cause massive and entirely justified outrage, and would be quickly bypassed by phishing sites regardless.)

Re: Chrome's Plan to Distrust Symantec Certificates

#137

Earlier quoted context omitted.

1. Uninstall the CA certficates the browser has pre-installed 2. Create and install own CA certificate 3. Download or create desired server certficates, sign them with own CA and install them I have not tried 1 but I regularly do 2 and 3. (Usually for monitoring outgoing encrypted traffic.) Anyway, the idea of your comment is spot on, I think. The process whereby users blindly trust browser authors has serious flaws.…

If the system by default without users doing anything said common popular websites were insecure, most users would just learn to click through (no matter how many clicks it took) and generally ignore all security warnings. It's crying wolf. You would have actually decreased overall security. (Or they'd just switch to a different browser without these problems). I understand the intent of your suggestion, and you're n…

I think if Chrome started showing alerts that the CA Reddit got it's cert from was sketchy, Reddit would go looking for a new CA. (And maybe given time the world would all end up using the Alphabet CA, which would presumably always have a five star rating....)

Re: Chrome's Plan to Distrust Symantec Certificates

#138

SWIFT is the only single entity trusted by all banks in the world. I think they would be a perfect fit for a CA to issue online banking certificates, since there is no way to get around trusting SWIFT as a bank, so they might as well trust them for their certificates as well, instead of trusting Symantec or any other CA. The less entities you have to trust, the better.

> since there is no way to get around trusting SWIFT as a bank

I understand banks are free to have some kind of direct-transfer mechanism between them, like internet peering, it would just be redundant.

But anyway, I would not trust SWIFT as gatekeepers of banking security. They're a prime example of a business that runs on COBOL written 40 years ago and they're not the paragon of progressive thinking in banking (SWIFT could torpedo Western Union overnight if they really wanted to) and finally, they already have a poor reputation in INFOSEC circles: https://en.wikipedia.org/wiki/2015%E2%80%932016_SWIFT_bankin...

Re: Chrome's Plan to Distrust Symantec Certificates

#139

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

Being cautious about entering data on a form is a cute idea but it doesn't work in reality. The web, with JavaScript loaded from multiple origins, doesn't work that way. These origins are practically invisible to you, they have complete access to the pages they are included in and you have no way of checking their certificates.

Re: Chrome's Plan to Distrust Symantec Certificates

#140

I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…

Being cautious about entering data on a form is a cute idea but it doesn't work in reality. The web, with JavaScript loaded from multiple origins, doesn't work that way. These origins are practically invisible to you, they have complete access to the pages they are included in and you have no way of checking their certificates.

I'm aware of this. At present, those scripts can be run from any origin using any of the many CAs the OS/browser trusts.
Post reply on HN