https://www.troyhunt.com/on-the-perceived-value-ev-certs-cas...
The Power to Revoke Lies with the Certificate Authority
21–30 of 89 posts
Re: The Power to Revoke Lies with the Certificate Authority
#22Earlier quoted context omitted.
Yeah but I thought EV certificates involved phone calls, manual checks of the website, some basic security compliance... All the kind of manual paperwork & background checks that the standard certificate would not do.
right. and he passed the checks because his perfectly legitimate company is also called stripe inc and is also in the US, just in a different state. now stripe could take this up with the courts about how ian is confusing consumers and so forth, and they would win. but they didn't - they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not…
Is there any evidence that Stripe had anything to do with this?
Re: The Power to Revoke Lies with the Certificate Authority
#23Re: The Power to Revoke Lies with the Certificate Authority
#24The idea behind EV's (to tie domain ownership to real-world legal entities) is sound, it's just that the implementation is poor. If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct respon…
Re: The Power to Revoke Lies with the Certificate Authority
#25"I found what looks like a flaw in a system but I didn't try to exploit it for real, look how clever I am"
So his mate registered a company with the same name as another company and got an EV cert. Well done. Everyone knew that was possible already, at least everyone who has gone through the process. It doesn't matter much:
1. Ian wasn't actually a phisher or criminal. If he had been, and had used that EV cert to phish Stripe customers, he'd have been reported to the police using the details from the CA and possibly prosecuted. Bear in mind he had to register a company in the USA, not Kazakhstan.
2. Therefore in reality it is very rare for phishers to use EV SSL certificates. Actually I've never seen it.
So is this a demo that the system is horribly flawed? I don't think so. It's rather similar to people who send 10 spams to some accounts they just registered themselves and claim they've found a way to beat a spam filter so the whole thing is useless ... well, no, you weren't actually a spammer so the filter did the right thing. You're testing a flaw you think sounds realistic but isn't. Another common case of this, someone who beats a DRM system on a game 6 months after it was released and then talks about how useless copy protection is, not realising that after 6 months almost all sales happened already so the system worked just fine from the developers perspective.
What about revocation? Is the CA exercising undue control here? Probably not. CAs have language in the contracts you agree to at the time about how you're not trying to misrepresent yourself as if you were someone else. Ian's argument that he registered a name that happens to be identical to a well known payment processor, but in another state, is technically correct, which is of course the best kind of correct. But the underlying purpose was clearly impersonation, which is a violation of the agreements and thus not only grounds for revocation, but to not do so would rather undermine the whole system - why should Ian get away with it when others do not?
If stripe.ian.sh had been an actual operating company that happened to have experienced an unfortunate naming conflict with the other Stripe, I bet the CAs would not have revoked. They'd have found some reasonable solution - probably by letting the cert continue, on the grounds that no malicious behaviour was taking place in violation of the agreements. But it wasn't - it was just a dummy site.
Overall I don't understand Scott or Ian's point. Yes, legal names aren't globally unique. Did anyone think they were? Yes, Chrome's EV UI is rubbish and the big players other than Apple tend to have an institutional dislike of EV certs because of historical clumsy attempts at market segmentation pricing by CAs, that were totally unreasonable for companies with lots of servers. Yes, EV is imperfect.
The alternative though is paypal-customer-centerr.com ... which is better, how, exactly? It isn't.
If Scott Helme or Ian Carroll don't like how EV works today, why not go find actual criminal abusers and propose specific improvements that would stop them - perhaps making Chrome's address bar work more like Safari's. Otherwise this is just another blog pointing out security stuff that doesn't really matter.
Re: The Power to Revoke Lies with the Certificate Authority
#26Here in the UK there is another problem with EV certs, there is no way of registering a "trading name" or "doing business as (DBA) name" against a company so you can only have an EV cert issues against your actual registered business name. If that is different from your trading name and what you use as your domain name then they are less than worthless. For example, if the company is "Widgets of London Limited" but t…
Re: The Power to Revoke Lies with the Certificate Authority
#27I think it's fine that they revoked the cert because Ian's site looked exactly like Stripe. The point he made still stands though: That the EV is pretty much only lipstick.
By "site", are you referring to the actual site, or the EV indicator? Because the site itself doesn't look anything like Stripe's[1]. [1]: https://stripe.ian.sh/
I think the current look was updated later.
Re: The Power to Revoke Lies with the Certificate Authority
#28Earlier quoted context omitted.
1: Look at the domain... https://www.paypal.com/.* https://www.stripe.com/* etc 2: PayPal/Stripe do have their one touch/sso stuff, if sign up with to that you'll have at least an indication if things go weird. Otherwise you are right. It's a problem but it's a problem with the web, not specifically any payment processors which are all honestly doing anything they can to make these issues a non-issue.
Looks at the domain can be deceiving because of IDN homograph attacks.
Re: The Power to Revoke Lies with the Certificate Authority
#29Re: The Power to Revoke Lies with the Certificate Authority
#30The idea behind EV's (to tie domain ownership to real-world legal entities) is sound, it's just that the implementation is poor. If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct respon…
But how would that help? Both Stripes would have a valid first class identity with valid keys. How are clients supposed to then check?