5 ms·
"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates." The fo
by reddiric 10y ago
"If you are building products that intends to connect to a Google property moving forward you need to at a minimum include the above Root Certificates."
The foundation of a more secure web apparently requires you to trust Google with the entire internet, using their properties as leverage to force it to be so.
- skybrian 10y agoYou may want to look into certificate transparency and who's supporting it.
- reddiric 10y agoThat's a different issue, and doesn't address what I wrote.
- zokier 10y agoActually it does address your point about trust; CT severely limits the amount of trust we need to place to any single participating CA, including now Google.
- skybrian 10y agoI think it's related? Since certificate transparency is a way of watching what's going on with all certificate providers (or at least the ones that use it), an organization that thinks Google's root is up to no good has a way of checking. It's after the fact, to be sure, but it matters for reputation.
- rmhrisk 10y agoGoogle has announced an effort to move all CAs to Certificate Transparency, here is a Threatpost piece on the topic - https://threatpost.com/google-to-make-certificate-transparency-mandatory-by-2017/121651/ https://threatpost.com/google-to-make-certificate-transparen.... They will already log their public certificates to CT and this will continue given their push for CT.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- PedroBatista 10y agoIt basically Google scratching their own itch and their PR people having to polish this stuff by inserting expressions like "more secure" and "moving forward". It's disgusting but pretty much corporate life 101.
- agl 10y agoGoogle has had an intermediate CA for many years (GIAG2) so, if you don't trust Google, this doesn't make things any worse for you.
- mastax 10y agoIs Google less trustworthy than Go Daddy? Or CNNIC? Or the Hong Kong Post Office? Yes the CA system is broken but framing that as an anti-Google argument seems silly.
- ori_b 10y agoGoogle isn't less trustworthy, but it is far closer to being a monopoly. I would like to bias towards a more decentralized infrastructure. Especially since Google is US based.
- throwaway91111 10y agoIn a decentralized model, how do you know who to trust? How do you get google's public key? How do you know that public key can be trusted?
- justicezyx 10y agoWhat do you mean by 'monopoly'? Simply mean used by the majority of the users? So any sufficiently good product is monopoly, assuming that they are goodness is beyond the threshold to be favored by the majority of customers. What do you want to say about Google's monopoly? Are Google going to hurt others and throttle effective competition? Was there any competition in CA market at all?
- quickben 10y agoRegardless of your personal opinion, the law and the historical record state otherwise. To answer your later questions: Too many essential services under one umbrella. Not quite. It's competition stifling. Yes. Yes.
- lmm 10y agoI agree in principle, but currently every CA is a single point of failure for the entire Internet, so adding more CAs makes things worse rather than better. We need something like DNSSEC/DANE to enable actual decentralization (where the Hong Kong post office could only sign Hong Kong domain names and so on).
- userbinator 10y ago"Trust Google Services"