Live data from Hacker News

The Power to Revoke Lies with the Certificate Authority

scotthelme.co.uk

71–80 of 89 posts

Re: The Power to Revoke Lies with the Certificate Authority

#71

Earlier quoted context omitted.

> Ian run a legit site, not phishing He originally had a site that looked extremely similar to stripe's official website: https://news.ycombinator.com/item?id=16939094

I can't find any copies of that in any cache showing it was ever actually online, simply mocked-up photos posted to social media.

Posted by Ian himself. Why would he go to the trouble of mocking it up?

Re: The Power to Revoke Lies with the Certificate Authority

#72
I always like the idea of what EV Certs are intended to be, I just don't think the browser exposure to general public users has any value.

Factoring in EV Certs for systems that are scanning the internet and trying to separate things that might need more validation...think news agencies and the search engines or social media that distribute their content. This illustrates both the benefit and the consequence of that model at the same time.

It would be ideal if there were some type of EV appeals committee to deal with revoked certs that could mandate a revoked EV be reinstated in a situation like this.

There is a place where using the EV model of more comprehensive verification can be beneficial...it's just not to the general public in a browser bar.

Re: The Power to Revoke Lies with the Certificate Authority

#73

Earlier quoted context omitted.

I can't find any copies of that in any cache showing it was ever actually online, simply mocked-up photos posted to social media.

Posted by Ian himself. Why would he go to the trouble of mocking it up?

Presumably to demonstrate that a phishing site using such a certificate would be visually indistinguishable from the targeted site.

Re: The Power to Revoke Lies with the Certificate Authority

#75
post #19

The idea behind EV's (to tie domain ownership to real-world legal entities) is sound, it's just that the implementation is poor. If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct respon…

>If we have a good idea and a poor implementation, then the correct response is to fix the implementation, not throw out the whole idea as fundamentally broken.

The point is, nobody wants to fix it, because CAs are still making money.

Re: The Power to Revoke Lies with the Certificate Authority

#76

Earlier quoted context omitted.

I can't find any copies of that in any cache showing it was ever actually online, simply mocked-up photos posted to social media.

Posted by Ian himself. Why would he go to the trouble of mocking it up?

There's a difference between resolving something locally or setting up a demo for the purposes of capturing screenshots and having a website resolve on the public Internet and serve that content.

Re: The Power to Revoke Lies with the Certificate Authority

#77
post #20

Earlier quoted context omitted.

By "site", are you referring to the actual site, or the EV indicator? Because the site itself doesn't look anything like Stripe's[1]. [1]: https://stripe.ian.sh/

The Tweet shows part of the site as identical to Stripe's: https://twitter.com/iangcarroll/status/940281927789146112 I think the current look was updated later.

It was screenshots taken for the purposes of demonstration and wasn't his publicly hosted site. Do you think that he'd take that kind of risk?

Re: The Power to Revoke Lies with the Certificate Authority

#78
post #49

I agree with the fundamental conclusion that, due to changes in the Internet, CAs are quickly becoming arbiters of what content is valid or not in the public's eyes -- a job they aren't ready for and never asked for. The article linked goes about discussing this issue in a hyperbolic manner and it commits a few critical thinking mistakes despite arriving at a valid conclusion. Briefly, I'm going to focus on just one…

He requested an EV certificate for his legal business name. He didn't cheat anything here and both Comodo and GoDaddy concluded that he met all of the requirements to receive an EV certificate. When multiple different companies all conduct the due diligence necessary to issue an EV certificate and come to the same conclusion, I think it's fair to say that he should have an EV certificate for Stripe as that is his legitimate legal business name.

Re: The Power to Revoke Lies with the Certificate Authority

#79
post #21

On EV certs, Troy Hunt rightly pointed that no one really cares about them and many major websites (amazon, youtube, facebook) don't even bother: https://www.troyhunt.com/on-the-perceived-value-ev-certs-cas...

I care :-(

Do you? Are you going to stop going to a site because it's missing a EV certificate?

Re: The Power to Revoke Lies with the Certificate Authority

#80

Earlier quoted context omitted.

The Tweet shows part of the site as identical to Stripe's: https://twitter.com/iangcarroll/status/940281927789146112 I think the current look was updated later.

It was screenshots taken for the purposes of demonstration and wasn't his publicly hosted site. Do you think that he'd take that kind of risk?

What kind of risk?
Post reply on HN