Live data from Hacker News

The foundation of a more secure web: Google Trust Services

security.googleblog.com

141–150 of 178 posts

Re: The foundation of a more secure web: Google Trust Services

#141
post #60
post #57

Earlier quoted context omitted.

Is Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.

Google isn't less trustworthy, but it is far closer to being a monopoly. I would like to bias towards a more decentralized infrastructure. Especially since Google is US based.

I agree in principle, but currently every CA is a single point of failure for the entire Internet, so adding more CAs makes things worse rather than better. We need something like DNSSEC/DANE to enable actual decentralization (where the Hong Kong post office could only sign Hong Kong domain names and so on).

Re: The foundation of a more secure web: Google Trust Services

#142
post #69

Earlier quoted context omitted.

Well, personally I think that most of us adjudicate too little value to TLDs. The point of DNS is to be hierarchical instead of one flat space, so imho all legacy TLDs should have been immediately deprecated the day ccTLDs were introduced, and countries should have been endorsed to maintain second level hierarchy (somewhat like .uk had for some time). But of course that train left the station 30 years ago... in the c…

Many websites are not country specific. They started somewhere and are headquartered somewhere, but it is not something users should need to remember.

Using the global TLDs for a global site is fine. But I wish there was a rule against using .com/.org/... domains for sites that are restricted to a single country (e.g. a shop that only ships to the USA should be under .us)

Re: The foundation of a more secure web: Google Trust Services

#143
post #65

You can now have a website secured by a certificate issued by a Google CA, hosted on Google web infrastructure, with a domain registered using Google Domains, resolved using Google Public DNS, going over Google Fiber, in Google Chrome on a Google Chromebook. Google has officially vertically integrated the Internet.

Funded mostly by you looking at Google Ads.

Nope. Funded mostly by you clicking at Google Ads. Looking is for free.

Re: The foundation of a more secure web: Google Trust Services

#144
post #141
post #60

Earlier quoted context omitted.

Google isn't less trustworthy, but it is far closer to being a monopoly. I would like to bias towards a more decentralized infrastructure. Especially since Google is US based.

I agree in principle, but currently every CA is a single point of failure for the entire Internet, so adding more CAs makes things worse rather than better. We need something like DNSSEC/DANE to enable actual decentralization (where the Hong Kong post office could only sign Hong Kong domain names and so on).

Why should the Hong Kong post office only be able to sign HK domain names? Are businesses in Hong Kong not allowed .com addresses?

Re: The foundation of a more secure web: Google Trust Services

#145
post #73

Earlier quoted context omitted.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.

Amazon have too far a head start on that one but it is ironic that google seem to be able to crawl and index amazon better than amazon can do internally.

Re: The foundation of a more secure web: Google Trust Services

#146
post #73

Earlier quoted context omitted.

What's remaining is: server written in Go, running on a Google server OS, located on a Google designed server appliance, which is centrally controlled by a Google designed microprocessor, which is finally manufactured in a Google owned semiconductor foundry. Oh, and the sand used for silicon purification is sourced from a Google-owned stretch of beach. I haven't considered the internals of the datacenter though...

What I am waiting for is a good shopping experience hosted by Google. Can for the life of my not understand why did still haven't done this because it would solve so many of their problems wrt ads and purchasing.

I do not think this would be allowed within the European Union.

Re: The foundation of a more secure web: Google Trust Services

#147
post #43

I don't think this is a bad thing. Instead of a third-party you trust (or rather, your user-agent trusts) vouching that Google's indeed Google, it's now Google vouching for itself, and you trust them by the virtue that they're Google. This ought not be surprising: presumably, who better to say that Google is indeed Google than Google itself? The reason everyone doesn't run a root CA is because it's difficult to coord…

If you trust Google that is. The independent third party no longer exist.

Re: The foundation of a more secure web: Google Trust Services

#148

I mean people don't trust Google's motives but I trust the certificate authorities less... How do we (or Google) know that the CIA and FBI can't create certificates from all the CAs because they have stolen/demanded the Root CA for them? If I was a TLA I'd want the ability to perfectly MITM anyone. I think these questions imply that there needs to be a better way to think about security and trust for web endpoints in…

That's why the NSA opened Let's Encrypt, isn't it?

Let's Encrypt respects CT: https://crt.sh/?Identity=%25&iCAID=7395

Re: The foundation of a more secure web: Google Trust Services

#149
post #141

Earlier quoted context omitted.

I agree in principle, but currently every CA is a single point of failure for the entire Internet, so adding more CAs makes things worse rather than better. We need something like DNSSEC/DANE to enable actual decentralization (where the Hong Kong post office could only sign Hong Kong domain names and so on).

Why should the Hong Kong post office only be able to sign HK domain names? Are businesses in Hong Kong not allowed .com addresses?

I would like to see a single responsible CA for each domain (which are allowed to hierarchically delegate). Country-specific agencies should only be able to sign domains within their country, and .com addresses (which should be reserved for genuinely international sites, though that's a separate argument) should be handled by an international CA that can a) apply some consistent international standard for how domain owners are identified etc. and b) be specifically held accountable for dodgy .com certificates

Re: The foundation of a more secure web: Google Trust Services

#150
post #149

Earlier quoted context omitted.

Why should the Hong Kong post office only be able to sign HK domain names? Are businesses in Hong Kong not allowed .com addresses?

I would like to see a single responsible CA for each domain (which are allowed to hierarchically delegate). Country-specific agencies should only be able to sign domains within their country, and .com addresses (which should be reserved for genuinely international sites, though that's a separate argument) should be handled by an international CA that can a) apply some consistent international standard for how domain…

So... one CA for each domain, leaving no competition? And which unwanted domain will LetsEncrypt be left with, then?

Back in the real world, we have multiple CAs who have accountability for lots of overlapping domains. You can wish for some other non-existent situation, everyone else has to make the best of the situation as it stands.

Post reply on HN