Earlier quoted context omitted.
Yeah but I thought EV certificates involved phone calls, manual checks of the website, some basic security compliance... All the kind of manual paperwork & background checks that the standard certificate would not do.
right. and he passed the checks because his perfectly legitimate company is also called stripe inc and is also in the US, just in a different state. now stripe could take this up with the courts about how ian is confusing consumers and so forth, and they would win. but they didn't - they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not…
The Power to Revoke Lies with the Certificate Authority
11–20 of 89 posts
Re: The Power to Revoke Lies with the Certificate Authority
#12Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
Re: The Power to Revoke Lies with the Certificate Authority
#13When I pay with PayPal I usually ask myself if the website I'm on right now is genuine. I check if it's https, I check if the name is on the cert (the green lipstick) and, most important, if my password manager trusts this site by let it search for credentials matching the current url. Oh,of course I'm not on a public wlan... Can't it be easier?
1: Look at the domain... https://www.paypal.com/.* https://www.stripe.com/* etc 2: PayPal/Stripe do have their one touch/sso stuff, if sign up with to that you'll have at least an indication if things go weird. Otherwise you are right. It's a problem but it's a problem with the web, not specifically any payment processors which are all honestly doing anything they can to make these issues a non-issue.
Re: The Power to Revoke Lies with the Certificate Authority
#14I'm not sure how EV certs have continued to be a thing for so long. Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
I first noticed that it wasn't intercepting my connection to my bank, and then after some experimentation, that turned out to be the pattern. Sounds stupid, but there you go, somebody uses EV as a signal for something.
Re: The Power to Revoke Lies with the Certificate Authority
#15I'm not sure how EV certs have continued to be a thing for so long. Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
Re: The Power to Revoke Lies with the Certificate Authority
#16Re: The Power to Revoke Lies with the Certificate Authority
#17I'm not sure how EV certs have continued to be a thing for so long. Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
I did a contract in a corporate environment where the SSL interception proxy passed-through any site with an EV certificate. I first noticed that it wasn't intercepting my connection to my bank, and then after some experimentation, that turned out to be the pattern. Sounds stupid, but there you go, somebody uses EV as a signal for something.
Re: The Power to Revoke Lies with the Certificate Authority
#18I'm not sure how EV certs have continued to be a thing for so long. Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
I really wouldn't care for a web shop etc.
Re: The Power to Revoke Lies with the Certificate Authority
#19If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct response is to fix the implementation, not throw out the whole idea as fundamentally broken.
Unfortunately, there's also not much that the CAs can do to fix this by themselves. If we want to have a digital representation of a legal entity's identity, the best way to do that is to have a first-class digital identity rather than the hack of a system we have today which attempts to create a poorly supported, non-portable identity on the basis of emailed paperwork and phone calls. Such a first class identity - with private keys controlled by the legal entity, entrusted to the entity when it was first created - will allow clients to verify the identity against the source which actually governs it.
I can understand the privacy concerns surrounding the creation of legal digital personal identities - the creation of a definitive population ledger that goes along with it etc. But for companies? That the US doesn't have such a solution for companies in this day and age is just myopic.
Re: The Power to Revoke Lies with the Certificate Authority
#20I think it's fine that they revoked the cert because Ian's site looked exactly like Stripe. The point he made still stands though: That the EV is pretty much only lipstick.