Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It seems this was supposed to go in Chrome 41, but was deferred to Chrome 42.

What is the official communications channel from Google on these matters? I can't find anything expect the blog post from September, and absolutely nothing on the supposed deferral. The deadline came and went and I was left crying wolf.

I need something to point to in order to get people to understand the severity of this, and Google is not making it easy.



I agree that the original article should be updated. The delay seems to be due to some "late-breaking chain building bugs": https://twitter.com/sleevi_/status/585429689646260224

This older Twitter thread kinda alludes to some problems with CAs being compliant in time: https://twitter.com/sleevi_/status/584010058897293313

(Ryan Sleevi works on PKI for Chromium)


Background: CAs often provide cross certificates signed with SHA1 to older roots for browsers that don't have the newer roots installed.


They also could do a better job of informing webmasters exactly what is wrong with their certificates. If you go to XKCD, for example, Chrome's handling of https is very scary-looking and it has a message about the site using "obsolete cryptography", but it doesn't call out SHA-1 as the culprit or point toward an article explaining what's wrong & how to fix it.


"Obsolete cryptography" does NOT refer to SHA-1. It refers to using old cipher suites which are not viewed as secure.

One of the security team engineers also acknowledged that this is an unclear warning and that they are working on it.

https://twitter.com/vtlynch/status/574301319428702208


What's also odd is that it says "obsolete security" in that section of the security pane, but it still has a green lock next to it, not the yellow warning. So the text says one thing and the iconography says another, which is very confusing.


Yes, I agree,Its not ideal. But I follow the industry very closely and I trust that Google's team is working on it and nearing some major improvements.


Especially considering the official announcement blog post still says Chrome 41.

http://googleonlinesecurity.blogspot.be/2014/09/gradually-su...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: