Browsers and OS vendors shipping CAs seems to be the root of the problem, in my mind. Those should be distributed by the service providers, who are the actual trustworthy entities in the user's minds.
Browsers and OS vendors shipping CAs seems to be the root of the problem, in my mind. Those should be distributed by the service providers, who are the actual trustworthy entities in the user's minds.
The chain of trust is not to tell your users to trust you. It's to tell your users not to trust me, even if I look just like you.
Were the certificate to contain an IP address (or IP addresses), it would need to be updated every time the site started or stopped using a public-facing IP address.
That's what HPKP does, basically, unless I'm misinterpreting what you mean with service providers.
HPKP is Trust on First Use, so it's not perfect, but the alternative - some kind of Web of Trust - is not really practical for non-technical, not-security-conscious users, IMO.
Sadly I understand https much better than alternatives, due to web hosting experience. I am trying to catch up.
I share your frustration and I understand that trying manage levels of trust a tough problem compounded by the fact that a user's expectations are fluid.
Meanwhile at work we're juggling dozens of certs left and right each with their own expiry as a handout to CAs. There's no reason why CAs cant sell me a cert that has a decade expiry. If the cryptography it uses goes bad, we'll just replace it. Why am I constantly buying these things?
Everything about CAs and browsers are wrong. Especially when many browsers ship with root certs from entities controlled by autocratic governments with zero accountability and involved in cybercrime and cyberspying. I'm giving incredible access to these nation states by downloading Firefox, Chrome, or IE. How is this "secure" again?
That's the point. Having some authority who did at least some minimal checking, to extensive checking, and who will verify you really are who you purport to be. Trust but verify probably plays a part in this.
But, remember, you don't have to go to HTTPS. There is no requirement for you to do so.
Cert companies only do a phone call check for the very expensive EV certs. There is no minimal to extensive checking. That is a scam.
Web tech is all https now. I can't even browse a lot of https sites with some of my older devices. There is a requirement and I dislike it.
What if a customer who trusts you returns to your site, but ends up on an impostor's site instead? He was no way to discern the difference.
Actually I called shutterfly.com on the phone about that mixed content issue. I emailed them screenshots of the error from 6 different operating system and browser combinations, from 3 other users even. They claimed nothing was wrong. They were serving javascript via http on an https page and told me I was wrong and needed to update java, for weeks, on the phone, in chat, and in email, and declined to send the report to their webmaster. Even those wanting to be trusted are incapable of using these tools, from what I have seen. The whole thing is broken.
You generally have to modify the root domain to host a random value in a text file the cert company gives you. This demonstrates that you have control of the domain.
Aka, minimal checking.
Granted, that doesn't prove that you're the domain owner, but if you aren't the domain owner and you've got enough access to pass that challenge, the real own has security problems a cert isn't going to fix so hey.
All things considered, it's a hell of a lot better than nothing.
What devices do you have that don't support TLS?
Also, the point is not to trust you or not, it's to trust that I'm actually talking to you and not a MitM.
That does not mean that you know something about Security.
> ... why should we trust you?
That's exactly the point. This is INTERNET, we don't trust anyone, it's a dangerous place to do such action... but we have to, otherwise it's better to go a live up in the mountain.
So, I prefer to trust Symantec/Google/DigiCert/etc... instead of some small business that does not even know the meaning of updating software or change default passwords.
The chain of trust it's a burden, I know, why we should trust anyone? But there has to be some level of trust between two parties, and, if we can have a third one (Like an escrow) that can ensure that trust I think it's great. Even using asymmetric encryption you need to trust the other party's public key...
A quick example of an unencrypted, cert-less network, an unsecure one with tons of vulnerabilities is the SS7 and the GPS systems... Since they cannot add Certificates to their BTS (base transceiver station) or their satellites, because of roaming technology, it's quite easy to set up an antenna an spoof them[1] and have full control over you phone and GPS[2]
[1] https://julianoliver.com/output/log_2014-02-13_17-17
[2] http://permalink.lanl.gov/object/tr?what=info:lanl-repo/lare...
That said, I am actually trying to move to a rather isolated place, and that is a perfectly valid option, so don't knock it.