What makes Chrome special here? AFAIK, every browser (FF, IE, Opera, you name it) treats HTTPS with problems as "extremely scary, alert the President" (which is, IMNSHO, absolutely correct behavior - "this site says it's HTTPS://whatever, but I'm unable to verify this, so let's crash and burn - it might just as well be https://evilsite.evil, for all I know"), whereas unsecured, plain HTTP is seen as "meh, whatever."
Moreover, "why can't Google fix the Internet?" is, essentially, saying "do away with the other CAs, and make Google the ultimate CA" - doesn't fix the problem, plus makes it worse.
(FWIW, there are cheap SSL certs out there which are signed by known CAs and thus don't trigger the security error.)
As I stated in my reply, that's not a bug, that's a feature; sorry to hear it's inconveniencing you, but there is currently no other way to distinguish between https://yourbank.example.com/ and a MITM by https://phishingsite.evil/
Replacing a CA-based chain of trust with a Google-based chain of trust makes no difference IMNSHO (except that Google would essentially own and 0wn the Internet; not a pleasant side-effect).
Comments
What makes Chrome special here? AFAIK, every browser (FF, IE, Opera, you name it) treats HTTPS with problems as "extremely scary, alert the President" (which is, IMNSHO, absolutely correct behavior - "this site says it's HTTPS://whatever, but I'm unable to verify this, so let's crash and burn - it might just as well be https://evilsite.evil, for all I know"), whereas unsecured, plain HTTP is seen as "meh, whatever."
Moreover, "why can't Google fix the Internet?" is, essentially, saying "do away with the other CAs, and make Google the ultimate CA" - doesn't fix the problem, plus makes it worse.
(FWIW, there are cheap SSL certs out there which are signed by known CAs and thus don't trigger the security error.)
yes, I picked on Chrome just because that's what I was using at the time, I am aware the problem probably exists on most browsers.
As I stated in my reply, that's not a bug, that's a feature; sorry to hear it's inconveniencing you, but there is currently no other way to distinguish between https://yourbank.example.com/ and a MITM by https://phishingsite.evil/
Replacing a CA-based chain of trust with a Google-based chain of trust makes no difference IMNSHO (except that Google would essentially own and 0wn the Internet; not a pleasant side-effect).