Live data from Hacker News

Digicert Withdraws from the CA Security Council

digicert.com

71–73 of 73 posts

Re: Digicert Withdraws from the CA Security Council

#71
post #70

Earlier quoted context omitted.

How does a U2F key even solve the problem of knowing that a website associates with a real identity? It may stop a phishing attack, but where do you get the initial trust to begin with? I think the issue is that we need to know that google.com can be shown to clearly be owned by Google, LLC, and not GoogleCo in a small African nation. (And also, presumably, that google.com is actually google.com, and not some weird s…

> I think the issue is that we need to know that google.com can be shown to clearly be owned by Google, LLC, and not GoogleCo in a small African nation. Google, LLC? Why not Google, Inc.? Wait, is it Alphabet, Inc.? Why do I trust companies from Palo Alto (or Delaware?) more than I trust companies from small African nations? I don't trust google.com because they're run by some Delaware corporation named "Alphabet." I…

It is perhaps ironic that your primary objection to my line of thinking is that it gates out smaller players and startups, potentially, but then you mention trusting google.com because it's baked into your browser, which of course, gates out everyone but one centralized monopoly deeming itself trustworthy. (Note: I have removed a litany of malicious Chromium-based browser installs from people's PCs in the last year, I am not sure convincing the average user to trust their browser is a good plan.)

And what about https://www.xn--80ak6aa92e.com/? How is the average user supposed to keep up with the latest and greatest ways to pretend to be someone else's URL? I mean, goog1e.com is likely to still be a reasonably effective deception to the average user. Should nobody ever click a link from anywhere, and solely find websites by memorizing the URLs and typing them in?

Re: Digicert Withdraws from the CA Security Council

#72

Earlier quoted context omitted.

letsencrypt destroying their business model, they are trying to find new sources of income.

I didn't look in the last few months, but most definitely when I did last look the reality is that Let's Encrypt and the strongly related "HTTPS Everywhere" movement actually drove growth for the _entire CA industry_ This is undoubtedly at least in part due to a halo effect. If Alice and Bob have $0 Let's Encrypt certs for their blogs about, respectively, an obscure species of tree frog and restoring muscle cars, whe…

I think that a lot of small customers moved from commercial CAs to letsencrypt. I don't even know a single reason not to use letsencrypt now. Sure, there will be new customers, but I'm not sure about old customers and it'll be worse as existing customers slowly would learn about free letsencrypt and migrate to it.

Re: Digicert Withdraws from the CA Security Council

#73

Earlier quoted context omitted.

If you want to know if a site is trustworthy , you want a certificate from their insurance company, not their CA. Someone who is promising to pay you real money if the site contains malware or a scam or whatever. Unfortunately this sort of insurance would probably be more, not less, expensive than EV certs.

That type of insurance is often called cyber insurance, and is pretty common among businesses. I work for a nonprofit--not even a tech company--and we carry cyber insurance and require all our technology vendors to carry it too. Personally, I would not be opposed to CAs requiring proof of cyber insurance in order to issue an EV cert.

"Cyber insurance" may reimburse the site operator for the liability they have to you for (say) being infested with malware. And that model seems to work OK for car accidents. But I think that only helps you (the site visitor) if you already have a practical ability to sue the site operator (particularly difficult if the site operator is on the other side of the globe, in a jurisdiction you know nothing about). What I'm proposing is that the insurance company offers to accept direct liability to site visitors, with well defined liquidated damages and arbitration processes so that it actually means something to the user.

If someone is offering that today, they aren't marketing it well. And again, actually signing the certificates would be a negligible part of the business (or the cost).

Actually, if I were in the insurance business I'd actually think about pushing this direction. If you could get the browsers to sign up for giving it special treatment it would probably greatly increase the size of the market. (Right now operators seem to mostly just escape significant liability for compromises)

Post reply on HN