Hacker News new | ask | show | jobs
by tcd 2729 days ago
LE cannot die, much like Wikipedia. Google et al would buy them before that happens.
1 comments

Transferring ownership or control of a root CA requires assent from the trust stores.

That's one (of several) reasons WoSign / StartCom was distrusted, they tried very hard to conceal the change in ownership of StartCom.

Assent might well be given, but it isn't automatic. This came up for Symantec selling their CA business, and also for other CA outfits doing internal reorganisations which wanted to be clear that these were paper exercises (e.g. for branding) and had no effect on which people controlled the CA in practice.

In the specific case of Google acquiring Let’s Encrypt, the fact that they control the majority of browser share means that it will get added to the Chrome trust list, and everybody else will have to go along.
There is not really a "Chrome Trust List". The Chrome browser does have Google-specific policies, but it doesn't use a Google trust store, it uses the OS supplied trust store, e.g. on Windows it consumes SChannel's Trust Store and the macOS version of Chrome uses the macOS Trust Store.

On a Google Android device, such as a Pixel, Google are responsible for the OS trust store, as they build the entire OS, but in practice it's basically the Mozilla trust store.

To the extent that we can say "Everybody else will have to go along" with anything when it comes to the trust roots, I'd suggest it's whatever Mozilla, a public charity, chooses to do. A brutally frank person might suggest that for-profit trust stores (all the big ones except Mozilla are for-profits) see considerable value in having unwelcome but necessary decisions made officially by somebody else before they "reluctantly" go along with them.

Also, Google is a very big company, the people who work on Google's Certificate Authority, the people who work on Chrome, and the people who co-operate with Mozilla are three separate groups at Google.

Sounds a technicality, what I know is chrome and Firefox independently distrusted Symantec. Google didn’t have to wait for Mozilla
Trusting and distrusting are not the same.