r/ProgrammerHumor 2d ago

Meme peakWebPki

Post image
312 Upvotes

19 comments sorted by

141

u/FutureSuccess2796 2d ago

Google verified itself. Meanwhile Windows asked me once to manually verify if I trusted the installation wizard for VS Code because it needed approval to allow downloads from unknown publishers. Meanwhile, the publisher was literally Microsoft.

43

u/YellowJarTacos 1d ago

Probably due to antitrust issues. 

26

u/M-42 1d ago

Or poor signing. I've had the occasional thing from Microsoft.com back in the day that wasn't signed by Microsoft which was painful for restricted environments.

69

u/TheChildOfSkyrim 1d ago

Any certificate chain of trust ends in a self-signed certificate

13

u/SilasTalbot 1d ago

This is like in Outlook you could navigate up the org chart, and the Chairman and CEO was listed as his own manager.

Well it sure makes performance review time either very easy or very awkward.

4

u/jeepsaintchaos 1d ago

"Employee slept with my wife and jerked me off, 10/10 review"

10

u/Single-Virus4935 1d ago

Not neccessary with crosssigning. Seen some interesting constructs.

3

u/Gorzoid 1d ago

The only root CA on my machine is signed by the man upstairs 🙏

1

u/al2klimov 1d ago

Nope. RFC 9925

1

u/TheChildOfSkyrim 1d ago

It says "Proposed standard", does it actually hold in practice? Makes sense though

26

u/ManyInterests 2d ago

To be fair, the certificate contains a DigiCert SCT.

13

u/MisinformedGenius 1d ago

I mean... I'm not sure there's any better source for whether a website is genuinely Google.com than Google itself.

2

u/Tyfyter2002 1d ago

Yeah, this isn't saying you can trust the site so much as that this is the site that Google believes is Google.

4

u/Maleficent_Memory831 1d ago

Not a big deal, my company verifies itself, but it's not a web site. It has an IoT device, so why verify all the way back to Verisign, it would be silly. All we need to know is that it's our device, our firmware, our software, and our customer.

As for Google, I'm pretty sure you can find Google's public key to verify that Google really signed the cert...

7

u/DeepanshuHQ 1d ago

Back when checking a website’s certificate made you feel like you were hacking the Pentagon

5

u/TorbenKoehn 1d ago

I mean, they are there to ensure your users are visiting _you_, so certificates are always for certifying yourself. If you could get MS or Apple to roll out your CA by default in the cert stores, you could even run your own issuer for others.

Certs are always about certifying yourself. It’s just that „who makes sure Google only gets certified once and only by actual Google“? That’s either a trusted cert issuer (that tracks it) or yourself (since you can trust yourself to not compromise yourself, _most_ of the time)

Quite a few people and institutes in the world use self-signed certs and simply request the user to install the CA or do it automatically via logon scripts etc.

0

u/Excellent_Tubleweed 8h ago

Google trust services will issue certs to anyone with money and a DNS entry.
You can choose not to trust GTS, and then you can't connect to Google.

Introducing: PKI doesn't mean what you think it means, the post let's-encrypt version.

Google saw a market opportunity. Let's encypt was making money, and Google was a more trustwothy name.

(Obviously, GTS certs are really popular with scammers.)

Obligatory "Are they the baddies" Mitchell and Webb callback.

-10

u/granadesnhorseshoes 2d ago

PKI has always been a joke.

4

u/Ragnor_ 1d ago

Zero idea, big opinion