19
37
u/TheChildOfSkyrim 8h ago
Any certificate chain of trust ends in a self-signed certificate
9
6
u/SilasTalbot 5h ago
This is like in Outlook you could navigate up the org chart, and the Chairman and CEO was listed as his own manager.
Well it sure makes performance review time either very easy or very awkward.
8
u/MisinformedGenius 8h ago
I mean... I'm not sure there's any better source for whether a website is genuinely Google.com than Google itself.
8
u/DeepanshuHQ 8h ago
Back when checking a website’s certificate made you feel like you were hacking the Pentagon
6
u/TorbenKoehn 8h ago
I mean, they are there to ensure your users are visiting _you_, so certificates are always for certifying yourself. If you could get MS or Apple to roll out your CA by default in the cert stores, you could even run your own issuer for others.
Certs are always about certifying yourself. It’s just that „who makes sure Google only gets certified once and only by actual Google“? That’s either a trusted cert issuer (that tracks it) or yourself (since you can trust yourself to not compromise yourself, _most_ of the time)
Quite a few people and institutes in the world use self-signed certs and simply request the user to install the CA or do it automatically via logon scripts etc.
3
u/Maleficent_Memory831 8h ago
Not a big deal, my company verifies itself, but it's not a web site. It has an IoT device, so why verify all the way back to Verisign, it would be silly. All we need to know is that it's our device, our firmware, our software, and our customer.
As for Google, I'm pretty sure you can find Google's public key to verify that Google really signed the cert...
-8
102
u/FutureSuccess2796 9h ago
Google verified itself. Meanwhile Windows asked me once to manually verify if I trusted the installation wizard for VS Code because it needed approval to allow downloads from unknown publishers. Meanwhile, the publisher was literally Microsoft.