* Disclaimer: Google employee, no connection to any of this cert stuff.
* Disclaimer: Google employee, no connection to any of this cert stuff.
Since the CA business model is based on selling digital signatures that meet specific requirements, the threat of those certificates not working as advertised is compelling.
On the other hand, the client vendors can't go overboard with requirements on existing "too big too fail" CAs because the alternative is having large portions of the Internet stop working in their products due to untrusted certificates.
Edited to add: Google doesn't run its own root program, they use the OS root store, which will be from Apple, Microsoft, or Mozilla (most Linux distros use the Mozilla list). This means that the requirements from Google are in addition to those of the OS that is being used.
To be fair, some things have improved: Debian (and maybe Ubuntu) now have the Mozilla trust store plus one additional root (SPI). That said, all you need is one bad actor for the system to fail, and it seems the only reason why SPI is there is Debian infrastructure relies on it—but that doesn't make SPI trustworthy. [2]
[1]: https://plus.google.com/105761279104103278252/posts/eVdB6X3N... [2]: http://anonscm.debian.org/gitweb/?p=collab-maint/ca-certific...
I have no love for Symantec but it doesn't feel right. I wonder if private negotiations have failed and this is Google trying to push the point?
Can you imagine if Mozilla tried the same stuff? I mean, they don't trust CACert any more after CACert wasn't able to verify itself (?) adequately, but this is on a different order of magnitude.
And here is a thread about a Chinese government CA that mis-issued certificates for Google domains: https://groups.google.com/forum/#!topic/mozilla.dev.security...
Google's argumentation that Symantec apparantly isn't able to properly assess themselves seems sound to me: if after being told about a specific issue they still are not capable of finding all instances of it happening, while outsiders can do so with the published information, then they they are missing critical abilities in this regard.
Compared to that, Google just forcing Symantec to be externally audited after it was shown that, not only have they issued wrong certificates, but also that they are unable to properly audit themselves, is being soft on them.
[1] https://blog.mozilla.org/security/2015/04/27/removing-e-guve...
If a browser vendor just kicked them out, users would abandon that browser - just imagine if 40% of your common websites stopped working.
1. Google is already my personal internet police, as a Chrome user. Everything from which SSL stack to use, to whether and how to mitigate weak DH keys, to what NPAPI plugins to use, to whether my browser vendor is going off and signing contracts with Adobe about porting Flash to a brand-new runtime, to what sandboxing is in use, is in Google's hands.
I suppose someone could, fairly easily, set themselves up as an intermediary between Google and me, auditing and patching Chromium if necessary, and running their own update server. (Arguably Linux distros do this.) And if so, they have the option of overriding these decisions. (And the Linux distros sometimes do, for things like the default trust store.) But so long as Google is writing this gigantic codebase that I couldn't possibly audit myself, they've not particularly gained any more power by caring about the CA system.
2. Google gets to be my personal internet police because Chrome is good; part of why I run Chrome (and I'm typing this from a Chromebook) is that out of all the participants in the market, I trust Google to be the best at protecting my security, in part because they've shown a willingness to do things like this, and in part because they're developing things like Certificate Transparency (and doing that negotiation with Adobe, and implementing seccomp mode 2, and so forth). I even prefer google-chrome to chromium on Debian, despite generally being a Debian fan, because I trust Google more to do quick security response and to make fewer mistakes. Google only gets to do this because Chrome is a choice by a significant fraction of internet users. Even Opera wouldn't be able to pull this off.
They need all parts to work optimally and securely, and they get to feel the heat themselves for everything that's suboptimal. So they're working on fixing all of it.
Google relies on certificates being accurate as much as we do, it's in everyone's interest for this to be happening.
Though I do admit I can see a slippery slope argument with Google's power.