Skip to content

Comment on Chrome and misleading security information

Comments

What makes Chrome special here? AFAIK, every browser (FF, IE, Opera, you name it) treats HTTPS with problems as "extremely scary, alert the President" (which is, IMNSHO, absolutely correct behavior - "this site says it's HTTPS://whatever, but I'm unable to verify this, so let's crash and burn - it might just as well be https://evilsite.evil, for all I know"), whereas unsecured, plain HTTP is seen as "meh, whatever."

Moreover, "why can't Google fix the Internet?" is, essentially, saying "do away with the other CAs, and make Google the ultimate CA" - doesn't fix the problem, plus makes it worse.

(FWIW, there are cheap SSL certs out there which are signed by known CAs and thus don't trigger the security error.)

yes, I picked on Chrome just because that's what I was using at the time, I am aware the problem probably exists on most browsers.

As I stated in my reply, that's not a bug, that's a feature; sorry to hear it's inconveniencing you, but there is currently no other way to distinguish between https://yourbank.example.com/ and a MITM by https://phishingsite.evil/

Replacing a CA-based chain of trust with a Google-based chain of trust makes no difference IMNSHO (except that Google would essentially own and 0wn the Internet; not a pleasant side-effect).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.