4 ms·
Maybe FF and Google should just become CAs? It would remove the extra step as currently both pinning and registering with existing CA are required?
by cornewut 12y ago
Maybe FF and Google should just become CAs? It would remove the extra step as currently both pinning and registering with existing CA are required?
- bottled_poe 12y agoWhy should we trust them?
- belorn 12y agoWith the current setup, people are trusting mozilla/google to: Give you the correct software, Update silently, Determine which CA certificates to trust by default, and Determine which certificates are valid by pinning. The CA is trusted to do: Determine which certificates are valid.
- tokenizerrr 12y agoNot really. For firefox anyone can build from source (see also iceweasel), disable automatic updates. For chrome it's mostly the same, but then for Chromium instead.
- unfamiliar 12y agoCan you verify that the binary download of Firefox is compiled from that source unmodified?
- gluxon 12y agoThere's work in progress to allow this. https://bugzilla.mozilla.org/show_bug.cgi?id=885777 https://bugzilla.mozilla.org/show_bug.cgi?id=885777
- belorn 12y agoFor people who build from source, all control is at the user. They are responsible for the security, and they do not need to trust anyone. The question about who should have trust invested in them do not involve them, as they operate outside the system.
- drdaeman 12y agoJust building from source doesn't guarantee anything. Firefox is giant. It shouldn't be hard for a malicious party — should one appear someday — to hide some tiny backdoor somewhere in a more-than-a-hundred-megabyte source code tarball. Verifying GPG signatures of the tarball could prevent some (but not all) issues, but from my observations it's rarely done. And when I've seen it done public key's origin wasn't thoroughly verified, just blindly `gpg --recv-keys`'d from keyserver.
- xorcist 12y agoThis comes up again and again. Sure, the individual users is unlikely to wade through the complete delta for every published version, but it's not uncommon for packagers to be involved upstream as well (with a few unfortunate outliers of course). Backdoors have been catched this way before.
- drdaeman 12y agoThere's a difference between "building from source" and "obtaining software from a trusted party". Your suggestion (trusting the packagers) implies the latter and is almost irrelevant to the former. If one trusts a team to catch possible issues, one may trust the binary this team builds as well.
- logicallee 12y agoYes, why should we trust our browser company with the security of our SSL connections. That's like locking your car with a key made by the company that manufactured it!
- Maakuth 12y agoThat must be a legal minefield as they'd then be in competition with established CAs that use their browser as sort of a platform (unfair competition or something). Being a CA also seems to be a messy business, I don't now if Mozilla would have the resources to do that. Google seems to have a CA of their own, but they don't seem to be signing certificates other than their own with it.
- tptacek 12y agoI've been told by people on those teams that the legal issues behind this (or any other interference with the CA system) is a big concern.
- lucb1e 12y agoThey are. Google for sure, and Mozilla maintains a list of them that ships with Firefox. If that isn't the ultimate level of trust (deciding which CAs your browser will trust) then I don't know what is.
- tptacek 12y agoBoth Google and Mozilla have their hands in some ways tied about which CAs they support. Their browsers have to work on the Internet as it is, not the Internet as they want it, and so both certainly include CAs that their owners would prefer they didn't. Also, of course, there's the fact that both Mozilla and Google give their users control over which CAs they include. The UI for that functionality is unfortunate. But on the other hand, if generalist developers really want to stick it to NSA, that's a good project they can work on without screwing over users with bad cryptography.