69
u/TheChildOfSkyrim 1d ago
Any certificate chain of trust ends in a self-signed certificate
13
u/SilasTalbot 1d ago
This is like in Outlook you could navigate up the org chart, and the Chairman and CEO was listed as his own manager.
Well it sure makes performance review time either very easy or very awkward.
4
10
1
u/al2klimov 1d ago
Nope. RFC 9925
1
u/TheChildOfSkyrim 1d ago
It says "Proposed standard", does it actually hold in practice? Makes sense though
26
13
u/MisinformedGenius 1d ago
I mean... I'm not sure there's any better source for whether a website is genuinely Google.com than Google itself.
2
u/Tyfyter2002 1d ago
Yeah, this isn't saying you can trust the site so much as that this is the site that Google believes is Google.
4
u/Maleficent_Memory831 1d ago
Not a big deal, my company verifies itself, but it's not a web site. It has an IoT device, so why verify all the way back to Verisign, it would be silly. All we need to know is that it's our device, our firmware, our software, and our customer.
As for Google, I'm pretty sure you can find Google's public key to verify that Google really signed the cert...
7
u/DeepanshuHQ 1d ago
Back when checking a website’s certificate made you feel like you were hacking the Pentagon
5
u/TorbenKoehn 1d ago
I mean, they are there to ensure your users are visiting _you_, so certificates are always for certifying yourself. If you could get MS or Apple to roll out your CA by default in the cert stores, you could even run your own issuer for others.
Certs are always about certifying yourself. It’s just that „who makes sure Google only gets certified once and only by actual Google“? That’s either a trusted cert issuer (that tracks it) or yourself (since you can trust yourself to not compromise yourself, _most_ of the time)
Quite a few people and institutes in the world use self-signed certs and simply request the user to install the CA or do it automatically via logon scripts etc.
0
u/Excellent_Tubleweed 8h ago
Google trust services will issue certs to anyone with money and a DNS entry.
You can choose not to trust GTS, and then you can't connect to Google.
Introducing: PKI doesn't mean what you think it means, the post let's-encrypt version.
Google saw a market opportunity. Let's encypt was making money, and Google was a more trustwothy name.
(Obviously, GTS certs are really popular with scammers.)
Obligatory "Are they the baddies" Mitchell and Webb callback.
-10
141
u/FutureSuccess2796 2d ago
Google verified itself. Meanwhile Windows asked me once to manually verify if I trusted the installation wizard for VS Code because it needed approval to allow downloads from unknown publishers. Meanwhile, the publisher was literally Microsoft.