3 ms·
"It's one of the Internet's biggest security flaws" - aww, you're killing me here :) We have looked at it. Repeatedly. First when porting Chrome to Linux (and
by sleevi 13y ago
"It's one of the Internet's biggest security flaws" - aww, you're killing me here :)
We have looked at it. Repeatedly. First when porting Chrome to Linux (and trying to decide what sort of UI there should be for NSS cert management). Then for ChromeOS. And then again, revisiting it in light of the OpenSSL migration.
The reality is, the certificate management/configuration UIs, of all platforms (Windows, OS X, Linux-via-Firefox-and-Chrome-which-just-copies-Firefoxes-PSM), is hard. It's hard to express the decisions. It's hard to explain how the branching and cross-certifications of CAs can affect trust decisions (eg: recall DigiNotar's cross-certifications).
And in the end, it's not where users are spending their time/being tripped up. Getting the lock icon into a more meaningful state is a far, far greater investment, with far, far more actionable returns in users security. The work of the Chrome Security Enamel team on this - especially Adrienne Porter Felt - has been focused on trying to improve this.
- tptacek 13y agoI understand why you're writing this. You think I'm saying, "the UI that users use to modify the root certificate store is so bad that it's the Internet's worst problem". I'm not saying that. I'm saying that the fact that there's only a UI to configure your root store, and not a UI to: * set policy for which CAs you trust with which domains * subscribe to policies published by trusted third policies * monitor which sites bind you to which CAs * easily opt in and out of trusting different CAs ... is the big problem. It's a UX problem, not a simple UI problem. There are additional features that need to be added, and that can be added, without litigating the whole CA system.