Google Chrome has stolen an important security feature from its rival

Google Chrome
(Image credit: Shutterstock)

Google is planning to follow in Mozilla's footsteps as the search giant has announced plans to run its own certificate root program/store for its Chrome browser.

While operating systems and applications use a “root program” or “root store” to verify the identity of software during installation, Chrome and other web browsers use root stores to ensure that HTTPS connections are valid. They do this by examining a website's TLS certificate to determine whether the root certificate used to generate it is included in a local root program/store.

Unlike Mozilla Firefox which includes its own root store, Chrome has been configured since its launch in 2009 to use the root store of the operating system it is currently running on. So on Windows machines Chrome checks a site's TLS certificate against the Microsoft Trusted Root Program and on macOS devices the browser does so using the Apple Root Certificate program.

In the future though, Google's web browser will use its own root store to determine whether HTTPS connections are valid.

Chrome Root Program

In a new post on the The Chromium Project's webpage, Google has revealed its plans to create its own root store called the Chrome Root Program. The new root store will eventually ship with all versions of Chrome though it won't be coming to Chrome for iOS.

At this time, the program appears to be in its early stages and Google has not yet provided a timeline for when the Chrome Root Program will go live. However, the company has published rules for Certificate Authorities (CAs), which issue TLS certificates for websites, so that they can be ready when the time comes. Google provided more guidance for CAs in its post announcing the Chrome Root Program, saying:

“As this transition occurs, CAs should continue to work with the relevant vendors of operating systems where Chrome is supported to additionally request inclusion within their root certificate programs as appropriate. This will help minimize any disruption or incompatibilities for end users, by ensuring that Chrome is able to validate certificates from the CA regardless of whether it is using the Chrome Root Store or existing platform integrations.”

By introducing its own root store, Google will be able to provide a more consistent experience and common implementation across all of the platforms its browser supports. Chrome's security team will also be able to step in and ban CAs that aren't following the rules more quickly. 

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)