Security Blog

The latest news and insights from Google on security and safety on the Internet

Maintaining digital certificate security

8 tháng 7, 2014
Share on Twitter Share on Facebook
Google

11 nhận xét :

Unknown nói...

I don't think 'Certificate Transparency' is all it is made out to be.

Why Google has abandoned enforcing certificate revocation via OCSP and CRL, is beyond me. You are the only ones with the position to get the CA's to return revocation information in a timely and meaningful manner - why not do that instead?

Once CT is running, it will just be THAT much easier for all CA's and CA resellers to just tie to that system and market to all the users of those certs (thusly annoying everyone more than they do already with their scanning to get the same data). At least with scanning there is some barrier to entry and time required to do the task...

Why not Hash the domains in CT and only allow 3rd parties to request the presence of the domain via hash (or something similar)? The way it is now, you are just providing SSL Selling Parties a direct marketing list. Google seems smarter than that...

Anyway, glad that this India NIC event seems reasonably well contained, in Chrome, at least. What actions has MSFT taken to limit impact on IE users?

lúc 14:05 8 tháng 7, 2014
Francophone Bose nói...

Could you please clarify what do you mean by Google Domains?

lúc 10:29 9 tháng 7, 2014
Unknown nói...

I would like to know whether other rogue certificates found under CCA. Also, whether the others were also issued by NICCA or some other authority under CCA, and if so, which one.

lúc 08:49 10 tháng 7, 2014
MLH nói...

Um. So is Google still formally opposed to cert revocation checks?

lúc 10:08 10 tháng 7, 2014
tlund nói...

If we could migrate over to DANE, we could do away with this entire CA structure. There would be no need to "trust" these hundreds of (possibly corrupt, possibly hacked) CA:s spread over the entire world.

A good first step would be to get DANE support (back) in Chrome ;)

lúc 12:12 10 tháng 7, 2014
Yago Jesus nói...

Do you know SSLCop ? http://www.security-projects.com/?SSLCop

lúc 13:13 10 tháng 7, 2014
Unknown nói...

Google, when will you start using DNSSEC (http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions) and DNS-based Authentication of Named Entities (DANE, RFC6698) to combat such "attacks"?

lúc 20:23 10 tháng 7, 2014
Unknown nói...

Hello,

I was wondering how you detected the rogue certificates?

Thanks.

lúc 09:40 11 tháng 7, 2014
Glen nói...

Could you do this for most CAs where they have an obvious scope, especially those operated by country governments?

lúc 14:00 11 tháng 7, 2014
KK nói...

CCA India confirms that suspension and revocation of NIC CA has been reverted from there end but still on Chrome SSL issued by NIC and other DSCs are not working on chrome and IE. My question to Google is that why Chrome is still not allowing it...

Thanks
Kaushlesh Kumar

lúc 02:35 28 tháng 7, 2014
ICS Cyber Security nói...

don't think 'Certificate Transparency' is all it is made out to be.
digital certificate

lúc 16:49 16 tháng 8, 2014

Đăng nhận xét

  

Nhãn


  • #sharethemicincyber
  • #supplychain #security #opensource
  • AI Security
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2024
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2023
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2022
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2021
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2020
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2019
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2018
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2017
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2016
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2015
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2014
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2013
    • thg 12
    • thg 11
    • thg 10
    • thg 8
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2012
    • thg 12
    • thg 9
    • thg 8
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2011
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
  •     2010
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 5
    • thg 4
    • thg 3
  •     2009
    • thg 11
    • thg 10
    • thg 8
    • thg 7
    • thg 6
    • thg 3
  •     2008
    • thg 12
    • thg 11
    • thg 10
    • thg 8
    • thg 7
    • thg 5
    • thg 2
  •     2007
    • thg 11
    • thg 10
    • thg 9
    • thg 7
    • thg 6
    • thg 5

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms