6 ms·
The comment you’re replying to thinks Step Two is good, but feels a bad Step Three is inevitable.
by psergeant 8y ago
The comment you’re replying to thinks Step Two is good, but feels a bad Step Three is inevitable.
- magicalist 8y agoWhy would existing CAs leave the market if they didn't before?
- geofft 8y agoI think the argument is that existing CAs with mediocre practices are currently profitable, but in the presence of Google competition will stop being profitable and decide to exit, and may not decide to return if Google leaves. (I don't think the scenario as a whole seems likely, but this specific argument is analogous to e.g. concerns about Uber and Lyft competing with taxies on VC-subsidized pricing that will run out one day, or the loss of SF laundromats thanks to laundry startups.)
- magicalist 8y agoExcept, again, there are sponsored non-profits in this space. What further distortion do you expect?
- askmike 8y agoLE is great for a lot of things. But it doesn't offer the wide range of SSL certs everyone requires, such as OV and EV certs.
- tialaramex 8y agoGoogle did not request and were not granted EV treatment for this CA. So even if it mints certificates with an EV OID in them that will get ignored in Firefox. Although the Google CA, Google's root trust programme, and the Chrome TLS implementation people are three distinct teams at Google, common sentiment among the technically savvy (which would include all three groups) is that EV is either entirely or largely pointless and nobody cares, so it would not make sense to request EV treatment. Your general thrust is right, there are other things CAs issue that Let's Encrypt does not, but the numbers still tell a story of solid growth even in the Web PKI, Let's Encrypt grew the market considerably, seizing 75% of a market that is now five times bigger than before doesn't squeeze out other people.
- manquer 8y agoLargely pointless to people @ Google is not a good measure. Customers still use it, and are willing to pay for it.
- tialaramex 8y agoCustomers still use and are willing to pay for homeopathy, but since it's ineffective my doctor doesn't offer it. Google knows EV is basically snake oil, so why sell it? I appreciate that there's a certain level of anarcho-capitalist sentiment in Hacker News, but lots of people run for-profit businesses that don't take the "If there's any possible way to make money, no matter how reprehensible, I will do that" approach. If you just can't stand for any for-profit business to ever do anything except to make as much money as possible, let me offer you a (very weak) economic justification you can cling to instead: Offering EV means you need to build a fairly complicated customer services operation, maybe a call center with verification specialists, a whole new team of people with skills your company doesn't have today. It is very unlikely that Google can make more profit on this weird niche business than by spending the same resources on, say, a minor improvement to advertising revenue. There, Anarcho-capitalists, do you feel all safe and cosy in the knowledge that if you squint you can pretend it was all just about money?
- nailer 8y agoTying a legal identity to a cert is not snake oil. It's a fundamental part of every crypto system, including PKI prior to GeoTrust making DV in 2003.
- geofft 8y agoIt's not a fundamental part of most cryptocurrencies: it suffices to have a private key be able to send and receive money from its own account, without knowing what legal entity controls that account. It's not a fundamental part of Signal; the cryptosystem only identifies phone numbers, not legal identities. Similarly, it's not a fundamental part of Keybase, which only identifies social media accounts. It's not a fundamental part of PGP; it's traditional to verify legal identity (and some users have a need for that), but it's not at all required and you can have a pseudonymous key in the strong set pretty easily. It's not a fundamental part of military encryption, where the legal entity is just "this country's military," but internal distinctions matter. It's not a fundamental part of Tor, which goes to lengths to lose track of the legal identity of its users. There are advantages to identifying the legal entity that controls a website, sure, but 99% of the advantage of SSL is identifying a site name so that cookies are only sent to the same site, JavaScript is only accepted from the same site, a bookmark opens only the same site, a link from elsewhere on the web opens only the same site, etc. And in most cases, "legal entity" is just a proxy for "entity I expect". When I visit gmail.com, I'm looking for the entity I previously visited at gmail.com; knowing that gmail.com is now Alphabet instead of Google doesn't really help me, but knowing that it's the same site does. When I register an account in person at First Bank of Springfield and go home to log in, I care less that the website I find is controlled by one of the many First Banks of the many Springfields than that it is the same entity I just signed up for an account with - and I can guarantee that by typing in the https URL they gave me on the welcome brochure.
- dagenix 8y agoWho requires these certs? I've always gotten the impression they are useful for 1) checking a box on some form; and 2) making more money for CAs. And, if its my job to check that box or to make money for a CA, well, that's fine. But, it terms of them actually having a real use, I'd love for someone to tell me what that real use actually is.
- askmike 8y agoEveryone who operates a website with users that can be the phishing targets. Plain certs (DV) only tell you that you are talking to a server that that has been validated to belong to a domain (and the taking is done encrypted). For example: https://twitter.com/musalbas/status/1038919152826757122 https://twitter.com/musalbas/status/1038919152826757122
- dagenix 8y agoThat assumes that a significant number of people a) know that Google has a EV certificate and b) actually check it. To the first point, I'm not sure that Google actually does have an EV cert - looking at Google.com, I think they just have a DV cert. And to the second point, I suspect that few people actually check if the cert is EV or DV (If they check that the connection is encrypted at all). Having an EV cert for yourwebsite.com does nothing to prevent fishing if people are directed to someotherwebsite.com.someotherwebsite.com. So, whats the point if going through the extra pain / expense of getting one?
- ubernostrum 8y agoThere's not a lot of point to EV. Google and eBay don't even EV their primary domains; given what high-profile targets those are for phishing, the fact that they're not EV should tell you something about its utility as an anti-phishing measure.
- rocqua 8y agoAs per [1], twitter does use EV certs, but not everywhere. It depends on the geographical location. The author of this article (Troy Hunt) never noticed this inconsistency, whilst he works in security. Given that he never noticed it, and the fact that I've never heard of anyone else noticing it. I'd say that even when high-profile targets deploy EV, it still does nothing. A possible exception might be banks. I've heard (I think in the HN comment thread of [1]) of people actually calling up banks asking why the name isn't in the green part of the browser. I know I check that address most often. I guess people are just most security aware when it comes to mixing the internet and money. [1] https://www.troyhunt.com/on-the-perceived-value-ev-certs-cas-phishing-lets-encrypt/ https://www.troyhunt.com/on-the-perceived-value-ev-certs-cas...