Google To Remove China's Root Certificate Authority From Chrome Over Ties To Forged Certificate

Last week, Google's security engineers wrote a post about an intermediate certificate authority (CA) called MCS Holdings that issued some unauthorized digital certificates for Google's domains. The intermediate certificate for MCS Holdings was issued by CNNIC, China's main root certificate authority. Google believes CNNIC is also responsible for that forged certificate and has decided to remove it from Chrome.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • kenjitamura
    Reaffirms my decision to use Chrome as my main web browser.
    Reply
  • Maxime506
    Good job Google.
    Reply
  • vaughn2k
    "For the users that CNNIC has already issued the certificates to, we guarantee that your lawful rights and interests will not be affected.." Yeah right...
    Reply
  • alextheblue
    They'll strike a deal before long.
    Reply
  • Achoo22
    That's great, so long as there is always a way for users to accept certificates Google deems insecure. What we can't have is a situation where overlord Google is the sole guarantor of web security, gatekeeper to all encrypted sites.
    Reply
  • hellogts
    They'll strike a deal before long.
    That's great, so long as there is always a way for users to accept certificates Google deems insecure. What we can't have is a situation where overlord Google is the sole guarantor of web security, gatekeeper to all encrypted sites.
    If you don't trust Google, don't use Chrome, simple.
    'Don't be Evil' - Google
    Reply
  • Achoo22
    If you don't trust Google, don't use Chrome, simple.
    Better to be able to use Chrome without trusting Google.
    Reply
  • ananke
    CNNIC was hacked and certificates stolen, hence Google is immediately shutting them off, to ensure the existence of "cloud" and "Internet" the way we know it :) Probably, this was related to the bank sham that IBM announced discovered yesterday...Of course, nobody wants to explain clearly.
    Reply
  • f-14
    2. For the users that CNNIC has already issued the certificates to, we guarantee that your lawful rights and interests will not be affected."

    RIGHTS? YOU HAVE NO STINKING RIGHTS IN CHINA, YOU TAKE WHAT YOU ARE GIVEN BY CHINAGOV AND LIKE IT OR ELSE! *POOF*
    Reply
  • shiitaki
    I have more respect for Google since they are willing to take a stand.

    Microsoft will ask how high when China asks them to jump. They never have and never will promote or protect the end user. Everything about MS is how to shovel more money to stock holders.

    I think there are simply too many Certificates anyway. It is a lot of work but maybe it is worth investigating the removal of 95 percent of them. I don't need any certs from mother Russia, Nigeria, or for that matter anywhere else I never go. And just to be fair, I don't need the five from the DOJ either.
    Reply