Chrome Requiring Certificate Transparency in 2017
groups.google.com
groups.google.com
https://blog.instantssl.com/ssl/certificate-transparency-cla...
If Google's own monitors would miss critical events that others didn't, they'd be blamed and shamed.
If they didn't share knowledge of critical events which other monitors for whatever reason couldn't detect, they'd be attacked in media.
The most plausible outcome is that all major monitors will share data openly. There's no point with a public certificate transparency scheme if they don't.
As for the security (ability to report on critical events) of individual monitors, you have to read up on the guarantees that the CT logs can provide.
[1]: https://www.chromium.org/Home/chromium-security/certificate-...
[2]: https://a77db9aa-a-7b23c8ea-s-sites.googlegroups.com/a/chrom...
So any internal domain and domain hierarchy is exposed to the general public who queries for the organization's domain in the CT log.
I wonder how this will work for "internal" domains issued off a private CA, though. Will this be enforced by chrome, or is this just a CA/B rule?
Google actually launched a separate CT log which allowed certain CAs that aren't usually "trusted", but still only from a specific list:
https://security.googleblog.com/2016/03/certificate-transpar...
Edit: Section 3.1 of the CT RFC:
the log SHALL publish a list of acceptable root certificates ... Logs MUST verify that the submitted end-entity certificate or Precertificate has a valid signature chain leading back to a trusted root CA certificate
>announced plans that publicly trusted website certificates issued in October 2017
Currently, CT logs have a list of roots that may submit to their log. If you run your own self-signed CA, you cannot (usually) use these logs, and there is a lot of effort and little benefit to running your own log setup.
CT tries to protect relying parties from bad issuers, but when the relying party is the same person as the issuer, it is not as beneficial.
Requiring CT universally, even for "private" CAs, provides detailed evidence for several kinds of problems, such as various laptop vendors who have pre-installed MITMing proxies. It doesn't prevent those kinds of behaviors, but it makes denials less credible.
When a laptop vendor is building the device that's being shipped, I don't think it's practical for a browser vendor to be able to expect to win that arms race.
> It doesn't prevent those kinds of behaviors, but it makes denials less credible.
Once you start doing more malicious modifications of the browser, it should be more obvious (to both you and anyone observing or doing forensics on your behavior) that you're doing something malicious.
I'm confused. How does CT help with phishing? I thought its purpose was to detect misbehaving CAs.
Of course, there's two sides to that coin.
Enter in a domain name, and you can see all certs known for that domain.
Chrome itself does not act as a monitor, that is left to domain owners. CT guarantees detectability, but only if someone's looking.
CT also has a gossip protocol that should help detect misbehaving log servers; I'm not too familiar with that protocol and whether Chrome has implemented any of it. That's an area where I guess there might be some privacy concerns to think about.
The fundamental idea is to make all certificate creation public, by putting it in a publicly auditable list. THis allows anyone to check that someone else hasn't given out a certificate for their domain, or for a large chunk of the internet etc.
In order to make that work, you have to make all certificates that aren't in that list unusable, and you do that by having the browser check that the certificate it is checking is in the list.
Auditors and CT gossiping are responsible for ensuring that the log servers are not misbehaving.
I suppose a client could act more like a monitor and download chunks of the log at a time, thereby hiding which site in the chunk they were interested in. That wouldn't be hugely efficient though.
I created a CA. I imported and added it to the trusted roots. Very useful for development.
eg Places using their own CA + certs for internal sites
That wouldn't be good. :(