{"id":11523,"date":"2019-09-11T14:26:52","date_gmt":"2019-09-11T18:26:52","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=11523"},"modified":"2020-08-25T10:18:43","modified_gmt":"2020-08-25T14:18:43","slug":"ssl-certificates-one-year-max-validity-ballot-fails-at-the-ca-b-forum","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/ssl-certificates-one-year-max-validity-ballot-fails-at-the-ca-b-forum\/","title":{"rendered":"SSL Certificates: One Year Max Validity Ballot fails at the CA\/B Forum"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Ballot SC 22\u2019s failure highlights the dysfunction at the CA\/Browser Forum.<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-131868947-300x300.png\" alt=\"\" class=\"wp-image-11533\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-131868947-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-131868947-768x768.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-131868947-1024x1024.png 1024w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">For now, at least, SSL\/TLS certificates will still have a maximum validity period of two years (or 27 months). The CA\/Browser Forum ballot that sought to shorten the maximum lifespan of SSL\/TLS certificates to one year failed when the voting ended yesterday afternoon. The final tally was 20 opposed, 18 in favor and two abstentions. The vote wasn\u2019t that close though, it fell well short of what was needed to pass from the Certificate Authorities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is now the second time the initiative to shorten certificate validity to a single year has been rejected. The last time shortening validity was discussed, <a href=\"https:\/\/www.thesslstore.com\/blog\/cab-forum-ballot-193\/\">two years was the compromise<\/a>. This time around the only compromise extended to the CAs was delaying the ballot\u2019s effective date back a month, from March to April 2020.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citing business disruptions and the pain points of their\ncustomers, as well as 4,000 customer survey aggregate results from three CAs\nshowing website owners opposed the change by 83%, the CAs voted down this\nmeasure by a count of 20-11. The seven browser vendors joined in supporting the\nballot, but ultimately it didn\u2019t matter on account of the CA vote. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But while that might seem like it\u2019s the whole story \u2013 it\u2019s\nreally just scraping the surface. This process laid bare the CA\/B Forum\u2019s flaws\nand likely deepened the divide between the browsers and the CAs. So, today\nwe\u2019re going to discuss the ballot, the CA\/B Forum and the absolute breakdown in\ncivility that\u2019s unfolding right now in this industry. Then we\u2019ll talk about\nwhat needs to change to fix it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Max Validity &amp; the CA\/B Forum (and a quick word on EV)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For those that aren\u2019t terribly familiar \u2013 and admittedly, we\ndo sometimes forget that our singular focus on PKI isn\u2019t shared by the masses \u2013\nthe CA\/B Forum is the industry body that collaborates on the \u201cbest practices\u201d baseline\nrequirements that govern Certificate Authorities and the issuance of public-facing\ndigital certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s the way the Forum is described <a href=\"https:\/\/cabforum.org\/wp-content\/uploads\/CA-Browser-Forum-Bylaws-v2.2.pdf\">in its own bylaws<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>The Certification Authority Browser Forum (CA\/Browser Forum) is a voluntary gathering of leading Certificate Issuers and vendors of Internet browser software and other applications that use certificates (Certificate Consumers).<\/em><\/p><p><em>Members of the CA\/Browser Forum have worked closely together in defining the guidelines and means of implementation for best practices as a way of providing a heightened security for Internet transactions and creating a more intuitive method of displaying secure sites to Internet users.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Now, before we go any further, a quick aside. There\u2019s a real debate over the future of Extended Validation UI. There are some very vocal parties at the Forum that argue it\u2019s not effective so it should be completely eliminated. There\u2019s also a strict adherence to bylaws. They\u2019re regarded as an artifact and are so sacrosanct they can upend a ballot over something as trivial as numbering, or the editorial process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And yet, eliminating EV UI with no eye towards a viable\nreplacement seems to contradict the CA\/B Forum\u2019s own bylaws. Or at least the\nspirit of them. We haven\u2019t even gotten to the third sentence of the bylaws and\nalready it\u2019s obvious the Forum is only handling half of its stated purpose.\nYes, it\u2019s working towards a more secure web. No, it\u2019s not even making an\nattempt to find a \u201cmore intuitive method of displaying secure sites to internet\nusers,\u201d which is one stated purpose of the Forum. The browsers are finding a\nbetter way to display \u201cunsecure\u201d sites, but that\u2019s not what the bylaws say, is\nit?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anyway, that\u2019s not what we came here to talk about. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re here to talk about max validity, and the fact that this is the <a href=\"https:\/\/www.thesslstore.com\/blog\/one-year-certificate-validity-is-about-to-be-on-the-ballot-again\/\">second time the push to shorten certificate lifespans to a single year<\/a> has failed. As we stated earlier, the first time there was a compromise. This time? Not so much. Ballot SC 22 was introduced by Google\u2019s Ryan Sleevi in August and came up for a vote from September 3-9.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why did SC 22 Fail?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you go back and read the comments from the CAs \u2013 and not\nwith a cynical, suspicious predisposition \u2013 you see that most of the Certificate\nAuthorities didn\u2019t object to the idea of shorter validity so much as the timing\nand the changes to how long validation information could be re-used. There were\ntwo major timing factors:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>It wasn\u2019t that long ago that SSL\/TLS certificate\nlifespans were shortened to two years. Customers don\u2019t care about deliberations\nat the CA\/B Forum, they care that they\u2019re now being asked to renew certificates\ntwice as often. That drives up their costs, not just financially but in terms\nof time spent and resources used, and potentially poses security challenges and\na greater risk of outages by requiring more frequent replacement.<\/li><li>The effective date for the ballot was March 1,\nthen it was amended to April 1, which really wasn\u2019t a help so much as it was a\nsarcastic act of passive aggression. CAs were requesting at least a year before\nthe change became effective. Google\u2019s rep gave them an extra month. Read into\nthat whatever you like.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond that, enterprise customers were concerned that replacing certificates yearly, at that scale, was too large an undertaking to be ready by next Spring. <a href=\"https:\/\/www.thesslstore.com\/blog\/4-ways-to-integrate-cyber-security-automation-within-your-enterprise\/\">Automating<\/a> by then just isn\u2019t feasible. According to one CA\u2019s customer survey, when it comes to major enterprises, 75% of the customers use no automation today and 9% only use \u201c1% to 10% automation.\u201d&nbsp; Another CA whose customer base is mostly small businesses, found out that among its 2,732 respondents 22% had never heard of any automation tools, another 36% used no automation, and 17% were \u201cnot sure.\u201d That created another debate that quickly devolved into name-calling, but we\u2019ll get to that in a minute.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The less discussed side of SC22<\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"242\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-Profile-With-Checkmark-Icon-Ve-264502603-242x300.png\" alt=\"\" class=\"wp-image-11528\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-Profile-With-Checkmark-Icon-Ve-264502603-242x300.png 242w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-Profile-With-Checkmark-Icon-Ve-264502603-75x94.png 75w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-Profile-With-Checkmark-Icon-Ve-264502603-768x951.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-Profile-With-Checkmark-Icon-Ve-264502603-827x1024.png 827w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-Profile-With-Checkmark-Icon-Ve-264502603.png 883w\" sizes=\"auto, (max-width: 242px) 100vw, 242px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Then there was the less obvious intention of the ballot, which was to reduce the amount of time CAs could re-use validation data. Now, there\u2019s a little bit of subtext here. There are elements of the Forum that feel that validation, specifically business authentication, is broken. That\u2019s part of the whole EV debate. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the dynamics at work in the discussion of validation is that the non-CA members (browsers) of the Forum generally have a theoretical knowledge of validation, whereas the CAs are actually performing it and have a different perspective owing to their experience with the process. Neither viewpoint is wrong. In a truly collaborative environment, the two differing perspectives could even be a strength. But as it stands, even validation is a contentious topic at the Forum.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Right now, you can re-use validation data for 27 months (13 months for EV). After the initial validation, a CA can issue any certificate you order with only a domain control check if you ask for a new domain. That means it\u2019s near instant. For large organizations this is a godsend. Reducing the amount of time that validation information stays \u201cfresh\u201d and can be re-used means organizations and CAs must validate more often. That consumes time and resources from both the CA and the organization getting the certificate. It\u2019s also another move that devalues higher-validation certs because the re-validation process is more burdensome.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As we stated earlier, it wasn\u2019t the max validity that was\nthe problem for many CAs so much as it was the validation restrictions. And the\ntiming. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CA\/B Forum Ballot SC22 \u2013 The Voting<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When push came to shove, the ballot failed with CAs 20-11.\nTo pass, this ballot needed two-thirds of the CAs and a majority of the browser\nvoters. It didn\u2019t even come close with the CAs. Here\u2019s the final breakdown of\nthe voting:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"779\" height=\"492\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/CAB-Forum-Ballot-SC-22-1.png\" alt=\"\" class=\"wp-image-11526\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/CAB-Forum-Ballot-SC-22-1.png 779w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/CAB-Forum-Ballot-SC-22-1-300x189.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/CAB-Forum-Ballot-SC-22-1-768x485.png 768w\" sizes=\"auto, (max-width: 779px) 100vw, 779px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The measure was overwhelmingly supported by the browsers.\nAll seven votes were in favor:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Apple<\/li><li>Cisco<\/li><li>Google<\/li><li>Microsoft<\/li><li>Mozilla<\/li><li>Opera<\/li><li>360<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Ok, now let\u2019s talk about the ugly fault-lines that this\nprocess exposed, and what can be done to fix them. Maybe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The CA\/B Forum \u2013 \u201cdamned if you do and damned if you don\u2019t\u201d<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Coming from the world of sports journalism and having only\nentered this space in the last few years, I have to admit, the CA\/B Forum might\nbe the internet\u2019s best argument against high school bullying. Feelings seem to\nget hurt easily. Things get petty quickly. And there\u2019s a power dynamic that\nlooms over every discussion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s how Jeremy Rowley of DigiCert described it.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u2026any CA voting [on this ballot] is \u201cdamned if you do and damned if you don\u2019t\u201d. I suspect almost everyone will wait until the last minute to vote, to see how the ballot is going to turn out, for a couple of reasons. <\/em><\/p><p><em>First, CAs are getting a lot of different input and some CAs believe there are some business advantages to opposing this ballot, regardless of the outcome. Any CA that votes for this ballot will have other CAs use that as marketing material against the voting CA. We saw this with the last change (from 3 years to 2 years) and with the underscore character deprecation.&nbsp; Regardless of outcome, with 85% of the customers answering the survey against the change in validity period, the risk is high that a CA will face some negative reaction if they vote in the affirmative.&nbsp; <\/em><\/p><p><em>On the other side, all of the browsers seem universally aligned with the change and the security reasons for the change are (imo) compelling. To avoid being dragged into the middle, the safest bet for a CA is to not vote. The second safest bet is to wait until the ballot draws out and then vote no if the ballot will pass.&nbsp; I dislike the politics on the voting so I\u2019m hoping calling attention to them will mix things up.<\/em><\/p><p><em>Second, voting \u201cno\u201d gives the CA someone to blame for the change that insulates the CA from ramification of the change. The blame then can be on the ballot voters for the shortened lifecycle. Angry customers can be deflected to the browsers\/CAs who vote yes&#8230;\u201d<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">DigiCert ended up not voting. Can you blame them? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dimitris Zacharopoulos is the current CA\/B Forum Chair, he\nrepresents the Hellenic Academic &amp; Research Institution\u2019s Certification Authority\nor <a>HARICA<\/a> and posted the following: <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>HARICA does not agree with further reducing the lifetime of TLS Certificates as it creates unnecessary burden to site operators. If the main problem we are trying to solve is Domain Validation and the fact that some domains are &#8220;changing owners&#8221;, thus putting at risk the new Domain owners as BygoneSSL demonstrated, we should look for alternatives rather than having millions of site operators replace millions of Certificates at a shorter timeframe.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">HARICA ended up abstaining.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This can\u2019t happen. DigiCert is one of the largest, most trusted CAs in the industry. HARICA\u2019s representative is the CA\/B Forum Chair himself. Both organizations felt it would be disadvantageous to even VOTE on a measure that will have a massive impact on not just the industry but the entire internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other CAs have privately admitted they voted \u201cYes\u201d for fear of reprisals. They just didn&#8217;t want to risk having &#8220;another gun&#8221; pointed at them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s indicative of the fact that something\u2019s wrong.\nSomething is broken. And again, it\u2019s just the tip of the iceberg.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Browbeating and a general lack of civility<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most common refrains that\u2019s used against CAs at the Forum is that there\u2019s a lack of research presented on their part. So, in anticipation of the discussion period and voting on ballot SC22, three CAs surveyed their customers: DigiCert, GoDaddy and Entrust Datacard, as noted above. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The surveys were immediately rejected by some of the browsers.\nAs the ballot\u2019s author, Google, writes:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>While I certainly understand that academic rigor is not the objective here, it&#8217;s important to consider these facts when evaluating the results DigiCert shared. I also wanted to help DigiCert here; as they&#8217;re laboriously working to summarize respondents&#8217; free-form text results, if the survey was spoiled, or if the desired objective was fundamentally unobtainable due to the selection method, perhaps it&#8217;s not worth that effort and not worth further discussion?<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">To be clear, he\u2019s telling DigiCert not to even bother with transcribing the write-in comments from its survey because he faults the methodology and doesn\u2019t view the data as worth the time. This is a CA sharing feedback from its own customers. Again, you can\u2019t win here.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When Entrust Datacard turned in its survey results the discussion turned to enterprise certificate management practices and the hesitation to embrace automation. Eric Mill, a fellow at TechCongress and non-CA\/non-browser associate member of the Forum argued this was even more of a compelling reason to vote for the change.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>That so many organizations continue to mistakenly believe that doubling their manual renewal rate would cause severe disruption, or that automation of certificate issuance is an unimportant aspect of their own organizational security and agility, is a compelling reason to proceed with this ballot and mandate reduced certificate lifetimes. The survey results make clear that many current enterprise customers are not prioritizing this work on their own, and that a mandate covering all CAs at once is likely the only effective way to drive progress here.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">And while that\u2019s a valid point, it also served as a catalyst for the deterioration of the good faith debate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dean Coclin is a former CA\/B Forum Chair and moved from\nSymantec to DigiCert when it acquired the CA. When he suggested moving the\neffective date back, Google\u2019s representative excoriated him.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u2026If CAs are unable to make configuration changes within 6 months, or if they&#8217;re concerned they&#8217;re unable to revalidate a fraction of their certificates sooner than expected, then I do fear that those CAs are in dire straights, and it may be time to discuss phasing out trust in them\u2026 Considering that the ecosystem needs to be prepared for replacing certificates with five days notice &#8211; for example, when it&#8217;s discovered that the CA was failing to validate certificates and instead issuing them for &#8220;Default City&#8221; in &#8220;Some-State&#8221; &#8211; I truly hope that 18 months notice is more than adequate. Certainly, I hope you of all people can appreciate the importance of ensuring customers are able to migrate away, in a timely fashion, from CAs that are or are being distrusted, and the challenges faced by these customers if their certificates become untrusted before they expire, or if they forget how to replace or revalidate.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The effective date was then moved back by a single month to April 1<sup>st<\/sup>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This comment is just dripping with subtext. And frankly, had it come from anyone besides Google it would\u2019ve JUST been in bad taste. But coming from Google? It takes on a much more ominous tone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It was <a href=\"https:\/\/www.thesslstore.com\/blog\/remove-trust-in-existing-symantec-ssl-certificates\/\">Google that pushed Symantec \u2013 where Coclin worked at the time \u2013 out of the CA industry<\/a>. And here is the same representative that prosecuted that case, implying \u2013 no not implying, outright suggesting \u2013 that any CA that can\u2019t comply with this ballot could be distrusted by the browsers. And then alluding to Coclin\u2019s own experience navigating the Symantec distrust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That would be like the government declaring eminent domain on your old farm, then showing up at your new farm and insisting, \u201cthis is my land and if you don\u2019t grow sweet corn, or can\u2019t grow sweet corn \u2013 by my deadline \u2013 we\u2019re going to take your farm.\u201d Then turning to you and adding, \u201cbut you already know about losing your farm, don\u2019t you?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And again, DigiCert didn\u2019t vote. <a href=\"https:\/\/www.digicert.com\/blog\/how-reduced-tls-ssl-certificate-lifetimes-to-one-year-would-affect-you\/\">It said it was against the measure on its blog<\/a>, but was browbeaten into not voting. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And it wasn\u2019t just DigiCert that experienced this glaring\nlack of collegiality. Doug Beattie, a VP at GlobalSign, noted that the ballot lacked\na \u201ccomprehensive security analysis\u201d and asked Google to provide some data in\nsupport of this ballot so that his organization could communicate it to\ncustomers. Not an unreasonable request:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>We need a list of issues and attacks that have resulted in, or have a high potential to harm the eco system and exactly how these proposed changes help more than they hurt.&nbsp; Including the reasons across dozens of emails and multiple lists isn\u2019t consumable by the community which will be most impacted by the proposed changes.&nbsp; <strong>Describe them without calling out specific CAs or organizations, intimidating the community, or demeaning those that have expressed their opinion in the past.<\/strong><\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The opposite happened. In a 1600+ word response Google\u2019s rep detailed four bug reports made against GlobalSign before concluding:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>I appreciate that you repeated your call here for the reasons, but you&#8217;ve continually skirted engaging on the Substance, and instead presented it as an argument about presentation instead, and so naturally, we haven&#8217;t been able to engage.<\/em><\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Google and its browser cartel<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"229\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-223887922-229x300.png\" alt=\"\" class=\"wp-image-11527\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-223887922-229x300.png 229w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-223887922-768x1008.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/bigstock-223887922-780x1024.png 780w\" sizes=\"auto, (max-width: 229px) 100vw, 229px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The reason I\u2019ve laid out these excerpts from the CA\/B Forum discussion period centering around Ballot SC 22 is to give examples of Google intimidating CAs. Google, by virtue of its positioning, exerts considerable influence. Its browser is the most widely-used by a huge margin and its search engine is dominant. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But it\u2019s not just influence over the CAs that Google leverages. It also has a lot of unseen influence over the browser makers. Google is one of Mozilla\u2019s biggest patrons and its economic health is largely contingent upon its search deal with Google, which helped grow its revenue by 8% in 2017. Earlier this year when Firefox was having connectivity issues, it accused Google of damaging it for years to come. <a href=\"https:\/\/www.zdnet.com\/article\/former-mozilla-exec-google-has-sabotaged-firefox-for-years\/\">Even the criticism had to be measured<\/a>. After all, Google\u2019s \u201ca partner.\u201d Google said it was a mistake. But regardless of its intentions \u2013 a message was received. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond that, Microsoft Edge and Opera both run on Google\u2019s\nopen source Chromium project. Mozilla and Apple both use Google Safe Browsing\nas their anti-phishing service. And all the browsers need Google\u2019s search and\nadvertising divisions behind them. Pissing off Google is dangerous. And that\u2019s\ncompounded by the fact Google\u2019s rep wields its influence like a cudgel. For\nexample:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>The Web PKI is full of stories like this, where users and well-meaning server operators are harmed by the CAs and the recalcitrant customers, such as yourself, and wholly rely on Browsers to do the Right Thing by the user and to protect their interests.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">And that all sounds great \u2013 what a noble talking point. Is it true though? Ehhh.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.thesslstore.com\/blog\/article-11-eu-copyright-directive-google\/\"><span style=\"color:#F07725\" class=\"color\">Google threatens to shut down its news service in Europe<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/google-and-facebook-manipulate-users-to-circumvent-gdpr\/\"><span style=\"color:#F07725\" class=\"color\">Google, Facebook manipulate users to circumvent GDPR<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/right-to-be-forgotten-google-loses-landmark-case\/\"><span style=\"color:#F07725\" class=\"color\">Google loses landmark &#8220;Right to be Forgotten&#8221; case<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/google-fined-57000000-for-gdpr-violations\/\"><span style=\"color:#F07725\" class=\"color\">Google fined $57 million for GDPR Violations<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/eu-fines-google-5-billion-for-android-practices\/\"><span style=\"color:#F07725\" class=\"color\">Google fined $5 billion for &#8220;anti-competitive&#8221; Android practices<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/happy-gdpr-day-google-facebook-hit-with-8-8-billion-lawsuit\/\"><span style=\"color:#F07725\" class=\"color\">Google, Facebook sued for $8.8 billion by EU privacy advocate<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/google-80-billion-conflict-interest\/\"><span style=\"color:#F07725\" class=\"color\">Google&#8217;s $80 billion conflict of interest<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/https-google-china\/\"><span style=\"color:#F07725\" class=\"color\">Google allegedly developing censored Chinese search engine<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/browsers-helping-https-phishing\/\"><span style=\"color:#F07725\" class=\"color\">Google&#8217;s updated security UI leads to explosion of HTTPS phishing<\/span><\/a><\/li><li><a href=\"https:\/\/www.thesslstore.com\/blog\/mass-revocation-millions-of-certificates-revoked-by-apple-google-godaddy\/\"><span style=\"color:#F07725\" class=\"color\">Google mis-issues, revokes thousands of digital certificates<\/span><\/a><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">And then there&#8217;s the recent settlement with the US Federal Trade Commission.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In fact, as <a href=\"https:\/\/www.cbsnews.com\/news\/google-antitrust-probe-48-u-s-states-launch-antitrust-investigation-of-google-dominance-in-search-ads-and-data\/\">50 US state attorneys general and the US Department of Justice launch an antitrust case against Google<\/a>, it might be worth pointing out the influence Google flouts, the fact it\u2019s a major supporter of the free CA Let\u2019s Encrypt, that it serves on two policy-making \u201cmodules\u201d of Mozilla, as well as the fact its made a multitude of moves to undermine OV and EV SSL certificates and reduce lifespans and validation limits, to align with Let\u2019s Encrypt\u2019s free, 90-day, automated DV-only issuance practices and business model. One might even wonder if all these proposals are intended to drive website owners to move their sites to cloud services that are also CAs, etc., which could more directly favor Google\u2019s own business model.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You COULD make a case it\u2019s consolidated its influence and is\nexercising excessive market power. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But that would conspiratorial. That\u2019s not what we\u2019re proposing. Our fix is much simpler. The CA\/Browser Forum Chair simply needs to hold all parties to account. Evenly. While I\u2019ve seen the chair call out bad behavior from CA representatives before, I\u2019ve never seen it come down on the browser side. The Forum\u2019s Bylaws are explicit about the level of professionalism and consideration that must be exercised by its participating members. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Almost none of the remarks quoted above are made in the\nspirit of those bylaws and some are, frankly, thinly-veiled threats. Considering\nthe current Chair is from a CA that opposed the ballot and then abstained, you\nwonder if Google\u2019s influence doesn\u2019t have some impact here, too. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CA\/B Forum is a phenomenal idea and it has the potential\nto be an example for how other industries can collaborate and regulate\nthemselves. But it has to start with collegiality and respect for diverse\nopinions. Nobody at the Forum is a \u201cbad guy.\u201d Nobody is looking to cheat or\nsteal. You have to extend that much faith for any debate to work. It\u2019s\nliterally the definition of a good faith discussion. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article wasn\u2019t fun to write. Nobody wants to spend time talking about why the CA\/B Forum is falling short or how the industry is starting to polarize and imperil itself. The fact that a group of CAs \u2013 which compete in the same space for customers \u2013 get along better with one another than with the browsers is all the indication you need that the CA\/B Forum is broken.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, let\u2019s fix it. Let\u2019s start treating each other\nprofessionally. Nobody has to be friends. You don\u2019t have to spend time together\noutside of the meetings. Nobody\u2019s going to force you all to go get a beer. But\ntreating others with dignity and respect is a kindergarten-level virtue. And\none that\u2019s best not forgotten if we want the CA\/B Forum to approach what it\nused to be and still has the potential to be again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Do you have suggestions on how we can improve the level of discourse at the CA\/B Forum? We\u2019d love for you to share them with us. <\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Ballot SC 22\u2019s failure highlights the dysfunction at the CA\/Browser Forum. For now, at least, SSL\/TLS certificates will still have a maximum validity period of two years (or 27 months)&#8230;.<\/p>\n","protected":false},"author":6,"featured_media":11529,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17,10200],"tags":[235,583],"class_list":["post-11523","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","category-monthly-digest","tag-cab-forum","tag-certificate-validity","post-with-tags"],"views":28904,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/09\/CAB-Forum-Broken-Feature.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=11523"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11523\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/11529"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=11523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=11523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=11523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}