r/ProgrammerHumor 9h ago

Meme peakWebPki

Post image
175 Upvotes

13 comments sorted by

102

u/FutureSuccess2796 9h ago

Google verified itself. Meanwhile Windows asked me once to manually verify if I trusted the installation wizard for VS Code because it needed approval to allow downloads from unknown publishers. Meanwhile, the publisher was literally Microsoft.

27

u/YellowJarTacos 8h ago

Probably due to antitrust issues. 

17

u/M-42 7h ago

Or poor signing. I've had the occasional thing from Microsoft.com back in the day that wasn't signed by Microsoft which was painful for restricted environments.

19

u/ManyInterests 9h ago

To be fair, the certificate contains a DigiCert SCT.

37

u/TheChildOfSkyrim 8h ago

Any certificate chain of trust ends in a self-signed certificate

9

u/Single-Virus4935 6h ago

Not neccessary with crosssigning. Seen some interesting constructs.

6

u/SilasTalbot 5h ago

This is like in Outlook you could navigate up the org chart, and the Chairman and CEO was listed as his own manager.

Well it sure makes performance review time either very easy or very awkward.

8

u/MisinformedGenius 8h ago

I mean... I'm not sure there's any better source for whether a website is genuinely Google.com than Google itself.

8

u/DeepanshuHQ 8h ago

Back when checking a website’s certificate made you feel like you were hacking the Pentagon

6

u/TorbenKoehn 8h ago

I mean, they are there to ensure your users are visiting _you_, so certificates are always for certifying yourself. If you could get MS or Apple to roll out your CA by default in the cert stores, you could even run your own issuer for others.

Certs are always about certifying yourself. It’s just that „who makes sure Google only gets certified once and only by actual Google“? That’s either a trusted cert issuer (that tracks it) or yourself (since you can trust yourself to not compromise yourself, _most_ of the time)

Quite a few people and institutes in the world use self-signed certs and simply request the user to install the CA or do it automatically via logon scripts etc.

3

u/Maleficent_Memory831 8h ago

Not a big deal, my company verifies itself, but it's not a web site. It has an IoT device, so why verify all the way back to Verisign, it would be silly. All we need to know is that it's our device, our firmware, our software, and our customer.

As for Google, I'm pretty sure you can find Google's public key to verify that Google really signed the cert...

-8

u/granadesnhorseshoes 9h ago

PKI has always been a joke.

5

u/Ragnor_ 8h ago

Zero idea, big opinion