Earlier quoted context omitted.
But how would that help? Both Stripes would have a valid first class identity with valid keys. How are clients supposed to then check?
In the current system, the client must query the CA that issued the EV cert for the legal entity data. This presents a number of problems: a) not all CAs will present enough distinguishing data to the client. Case in point: "Stripe Inc. [US]" b) No consensus between CAs as to who will issue a cert for a given legal entity. In other words, there is such a thing as a CAA record for DNS and DV certs, but no such thing f…
(b) Why is this a problem?
(c) Is there any evidence of demand for those usecases? How would you even present them to the users in an understandable way?
"Certificate Authorities are not in the business of establishing identity and so they are fundamentally doomed to doing a poor job of verifying identity."
I don't see how that follows. In fact, I don't see how that's even possible. Whenever you do business with any entity besides the national registry - be it a bank, insurance company, notaries, or even another governmental department - they have to verify your identity. CAs just happens to give you a digital affidavit of the results.
Instead of trying to coerce CAs into the identity business because of the inflexible and glacial pace at which government moves, we should be pressuring government to adopt more modern identification practices.
I disagree; we already have problems with too-big-to-fail CAs; governments are even worse. A CA can be told "follow the CAB Forum rules or get kicked out". But you can't distrust a government when they're the only issuer for the sites of the whole country.
Low-coupling is not just good in software development.