Security Research: Chrome Removes “One Google Log” Requirement from Its CT Policy

Yeah I think it was about time. I've always been a bit concerned with the "our Google logs need to be online, or you can't issue a certificate"-policy. It's essentialy always been a single point of failure for all CA's, ever since embedded SCTs became the standard. Google is right that there were some bad CT log operators in the past, but I believe the situation has improved a lot over the years and CT availability is much better now.

An example where a Google CT Log outage brought down Let's Encrypt is here: 2018.11.30 Production Google CT Log Submission Failures

7 Likes