4 ms·
I don’t know whether they pay for Google but Google can dictate many things; otherwise they drop certificates from Chrome and this has happened.
by nicce 1y ago
I don’t know whether they pay for Google but Google can dictate many things; otherwise they drop certificates from Chrome and this has happened.
- akerl_ 1y agoYou're thinking of the CAB, which dictates which CAs are trusted. Google is a participant in that. The things they dictate are public and have to do with security requirements, not whether or not they pay Google money.
- NoahZuniga 1y agoThis is not true! CAB is a place where CAs and browsers agree on what the rules for CAs should be. Google, Mozilla, Microsoft and Apple all administrate their own root stores which individually decide what CAs are trusted on their platforms. Individual root stores decide on the rules for inclusion in their stores themselves, but these rules are essentially: You follow CAB rules + a few extra things. Mozilla for example requires (besides CAB rules) that whenever a CA becomes aware of an issue, they post a bug to bugzilla and get their shit together pretty quickly and keep mozilla up to date on what they're doing.
- akerl_ 1y agoThis would feel a lot more like a relevant nit to pick if there were actually meaningful differences where I might go get a TLS cert and find it's trusted in Chrome but not Firefox or vice versa.
- NoahZuniga 1y agoChrome vs Firefox doesn't matter that much, but more significantly windows trusts more CAs than Chrome and Firefox. Not sure about the exact amount, but it seems to be somewhat significant amount. You can take a look at https://www.ccadb.org/resources https://www.ccadb.org/resources I looked at it but couldn't quickly get a number, so no number in my comment.
- NoahZuniga 1y agoWell, I do! And Google doesn't get paid! > otherwise they drop certificates from Chrome and this has happened. As far as I know, all the CAs Google dropped, this was because the CA misbehaved and misissued certs or was obviously failing at their job. Also, all CAs google has removed from their root store have also been removed by mozilla (or weren't removed because mozilla never included them).
- cptskippy 1y agoWhen did browsers stop respecting CAs managed at the OS level?
- nicce 1y agoIt has been a while, by default Chrome trusts only certs in Chrome Root Program.