good point. ok, I should probably think carefully before inventing a security standard 'on the fly'!
I guess I was thinking along the lines that I could add my site to a Google service (just like Analytics) and when people accessed my site (https), Chrome could talk directly to Google and confirm the site authenticity, same way CA's work I guess, but run as a free service.
But as noted in another comment, anything vendor specific would probably be a bad thing for the web.
And why exactly would Google (or anyone else) provide this service for free? (Well, except for the ability to do various nasty MITM stuff; but they have that "do no evil" motto - seems legit)
Sounds like "but I dont waaaaaaaaahnt to pay any money for services that I need! I don't care that infrastructure isn't cheap, I just want my free lunch."
Comments
Without verifying the identity of the site somehow, you are vulnerable to a mitm attack. So no, it's not a separate issue.
What is your proposed site authentication mechanism that Chrome should use (and does it scale to Firefox, Safari, etc)?
good point. ok, I should probably think carefully before inventing a security standard 'on the fly'!
I guess I was thinking along the lines that I could add my site to a Google service (just like Analytics) and when people accessed my site (https), Chrome could talk directly to Google and confirm the site authenticity, same way CA's work I guess, but run as a free service.
But as noted in another comment, anything vendor specific would probably be a bad thing for the web.
And why exactly would Google (or anyone else) provide this service for free? (Well, except for the ability to do various nasty MITM stuff; but they have that "do no evil" motto - seems legit)
Sounds like "but I dont waaaaaaaaahnt to pay any money for services that I need! I don't care that infrastructure isn't cheap, I just want my free lunch."
yep, that is exactly what it sounds like!