> This [well protected] certificate must both be issued from a trust hierarchy [which isn't Google and]
You should check out the issuer on the google.com certificate :)
Also, certificates are public data. They're not meant to be "well protected", they're sent to everybody connecting to the website. Maybe that's the misunderstanding? The private key is not issued by the certificate authority, it's issued by the server's operator. The CA only ever sees the public key.
How did you go from "chromium wants servers to support multiple certificates" to "chromium wants servers to support multiple certificates so they can put in their own certificates and MITM you"? Don't cloudflare and other CDNs already have the ability to MITM people given that they control the certificates? Why does google need this elaborate conspiracy to MITM people?
I also find it hypocritical that Google wants a multi-certificate architecture when they won't allow sysadmins their own certificate: https://issuetracker.google.com/issues/168169729?pli=1
It's probably a downstream effect from iOS not allowing third party rendering engines on ios, and the API for safari webview doesn't allow developers to swap out the TLS stack.
>I also find it hypocritical that Google wants a multi-certificate architecture when they won't allow sysadmins their own certificate: https://issuetracker.google.com/issues/168169729?pli=1
It really isn't. The linked issue seems to revolve around allowing root CAs to be added without user involvement, which presents privacy/security issues. Meanwhile being able to support multi-certificate in this context is motivated by being able to use newer cryptographic algorithms while still being able to support legacy devices, eg. presenting ECDSA certificate to modern devices but presenting an RSA certificate to decades old IOT devices that only support RSA. I don't see how that's contradictory with "we don't want to allow installing CAs behind users' backs because it might be abused to spy on them".
2. oh, you don't have a Google cert store cert in your bundle? why would you not want the best and free cert? seems suspicious, going to lower your google rank.
3. now that everyone have a google cert, chrome switches to using only that.
convoluted, yes, but then you have the exact same setup as today, with google making all the decisions
2. Google isn't a transit provider. Therefore they aren't really in a position to abuse their position to MITM traffic.
3. Google already controls the chrome browser itself. If they want your data they don't have to MITM you, they can just upload it after it's been decrypted by TLS
2 they already do things like hitting THEIR dns servers for all links on a page you're reading "for performance". you have no idea what is in play here if you think "omg google is going to phish me my bank password with a fake login page". you're way out of your water here.
3 they can't because of backlash and that would move people to other browsers. they have to slow boil you. see point 1
"If you handed Professor Quirrell a glass that was 90% full, he'd tell you that the 10% empty part proved that no one really cared about water." -- HPMOR