4 ms·
Google Chrome (along with Mozilla, and eventually the other root stores) distrusted Symantec, despite being the largest CA at the time and frequently called "to
by agwa 8mo ago
Google Chrome (along with Mozilla, and eventually the other root stores) distrusted Symantec, despite being the largest CA at the time and frequently called "too big to fail".
- notepad0x90 8mo agoGiven how ubiquitous LE is, I think people will switch browsers first. non-chrome browsers based on chrome are plenty as well, they can choose to trust LE despite Chrome's choices. Plus, they had a good reason with Symantec, a good reason to distrust them that is. This is just them flexing, there is no real reason to distrust LE, non-web-pki does not reduce security.
- nightpool 8mo agoGP gave a very good reason that non-web-PKI reduces security, you just refused to accept it. Anybody who has read any CA forum threads over the past two years is familiar with how big of a policy hole mixed-use-certificates are when dealing with revocation timelines and misissuance.
- account42 8mo agoThere was no good reason given only a "trust me bro".
- sam_lowry_ 8mo ago> non-web-PKI reduces security How exactly?
- notepad0x90 8mo ago"it's complicated" is not the same as "it's insecure". Google feels like removing this complexity improves security for web-pki. Improving security is not the same as saying something is insecure. Raising security for web-pki is not the same as caliming non-web-pki usage is insecure or is degrading security expectations of web-pki users. It's just google railroading things because they can. You can improve security by also letting Google decide and control everything, they have the capability and manpower. But we don't want that either.
- account42 8mo agoHalf the web didn't rely on Symantec for free certificates. They do rely on LE.
- direwolf20 8mo agoIf LE is distrusted, we all stop using TLS and go back to letting the NSA read everything. LE is the only reason HTTPS is now ubiquitous.
- b112 8mo agoIsn't that a really, really juicy target though?
- Ayesh 8mo agoLetsEncrypt doesn't see your private key when you obtain the certificate. So no, it's not _really_ a juicy target.
- notepad0x90 8mo agoWhy not just stop using Chrome and start using any of the Chrome-based alternatives in instead?
- direwolf20 8mo ago