It's not at all clear to me that this prevents the internet from getting more secure.
Their proposal doesn't actually stop SHA-1 attacks. If an attacker can forge a SHA-1 cert, they can set up a MitM in which the victim talks exclusively to the attacker's server. Facebook's servers won't be contacted, so the downgrade-proof logic on Facebook's servers won't even be executed. The attacker's server will present only the forged SHA-1 certificate, which web browsers will accept in the name of backwards compatibility. Long-term, browsers will stop accepting SHA-1 certificates, but this is not scheduled to happen until 2017.
> It's not at all clear to me that this prevents the internet from getting more secure.
Two ways this prevents the Internet from getting more secure:
1. Their proposal would make it possible to obtain SHA-1 certificates past December 31, 2015, which means there's more time for an attacker to exploit a collision to forge a cert. It's important to understand that exploiting a SHA-1 collision requires a certificate authority to issue you a certificate, so if no one is able to find a SHA-1 collision in the next 19 days, the Internet will be safe from SHA-1 collisions in 2016 even if browsers continue to accept SHA-1 certificates until 2017. Allowing continued SHA-1 issuance removes this safety net.
2. It sends the message to companies that deadlines can be ignored because they'll be pushed back at the last minute. This will make it difficult to deprecate insecure practices in the future.
I agree about the political part of the issue, but on the other hand, the SHA-1 deprecation is one of the most proactive things the CA/Browser Forum has done. Having it go not quite perfectly is still a vast improvement from reactively deprecating things only when they are fully insecure.
b) may help prevent collision attacks, but I have a hard time viewing a) (requiring downgrade-proof cert switching) as anything but security theater.
Edit: it's not even clear to me that b) is an integral part of Facebook's proposal. Their blog post says (emphasis added): "Such verification can be automated or manual, and appropriate measures can be put in place to reduce the risk of a collision attack. Those protections could include requiring LV applicants to have already passed OV or EV verification" [https://www.facebook.com/notes/alex-stamos/the-sha-1-sunset/...] CloudFlare's blog post [https://blog.cloudflare.com/sha-1-deprecation-no-browser-lef...] doesn't mention it at all.
Alas, we already more or less live in this world. If old standards were burned down without remorse more regularly, I'd think we'd see many things done differently. "But think of the pacemaker in the children's hospital" has unfortunately been the order of the day for quite some time.
Of course there will still be heaps of SHA-1 out there from private roots, but at least the rest of the world can move forward.
It means people can keep using their insecure clients instead of being forced to upgrade to something secure.
SHA1 isn't great, but it is certainly better than plaintext communications.
[1] http://thenextweb.com/facebook/2014/01/29/facebook-passes-1-...
I should be clear that SHA1 shouldn't be used for cryptographic purposes that require high amount of trust, but for your average everyday FB status updates it is probably fine when coupled with other protections.
P.S. that's basically the state of SMTP encryption, which is quite sad.