Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So Firefox doesn't enforce CT, while everything else does?

This + some of the other news about how they handle privacy make me doubt how prudent it is to use Firefox, from a security/privacy perspective :(



That's correct. I believe one obstacle is the consideration that Google + one other (the policy in Safari, Chrome and Edge) doesn't look like a very neutral policy, but it would likely now be impossible to implement any other policy.

However, although Firefox doesn't check SCTs, I believe you can add an extension to do this with the same policy everybody else has. Also, in practice all CAs in Mozilla's trust programme more or less have to use CT because Mozilla's incident process assumes you have working CT logs.

But yes, it would definitely be better if Firefox just checked SCTs even if they have to suck it up on the policy neutrality for compatibility reasons.

It would also be be nice if all clients that check SCTs implemented a Gossip protocol, and some other steps to complete CT as originally conceived. As shipped, today's clients would not reveal e.g. a split horizon CT log visible only to some particular group. It's just that we have every reason to think that this tree is bare of fruit, and so meticulously searching the highest branches is a much higher cost for likely no extra reward.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: