3 ms·
I manage SSL operations at Google and, as far I can tell, this is all nonsense. It's too long to deal with point-by-point, but I can do a few: * It's not odd
by agl 11y ago
I manage SSL operations at Google and, as far I can tell, this is all nonsense.
It's too long to deal with point-by-point, but I can do a few:
* It's not odd that a cert for * .google.com would be served for google.fr. Check the SANs.
* Google does not use EV certificates.
* Google's frontends have many IP addresses. Seeing differences at different times and places is normal.
* Our leaf certificates really are issued for only a few months.
* We will be off SHA-1 by the end of the year but, at the time the article was written, one certainly could have received a SHA-1 signed certificate from us.
* http://clients1.google.com/ocsp http://clients1.google.com/ocsp is our OCSP responder and, yes, you'll get 404 unless you send a correct OCSP request with a Host header.
- dsl 11y agoI just came here to point out the same thing. This is just the ramblings of someone with a medium level of technical experience and a high level of paranoia drawing some very odd conclusions.
- codinghorror 11y agoExcellent to hear from a confirmed source, this initially read very tiny print Dr. Bronner bottle to me as well, but I wasn't sure.