Earlier quoted context omitted.
> It's quite unlikely that an EV cert would be issued for washingtonpostnews.com I think the https://stripe.ian.sh story argues otherwise - it would be pretty easy to start an LLC named "Washington Post News" in some other state and have the government agencies be fine with that. (In fact, for the specific case of Washington Posts, half of all US states have a city/town named "Washington.") Also the more practical pr…
This is one example, sure, but EV does, in general, work. And the reason why is not because it's an ironclad indefeatable process for proving you are legitimately a major trustworthy party: It's a frustrating pile of hoops to jump through. The arcane and archaic nature of getting an EV gates out malicious actors pretty effectively. If you go through all of the process to get an EV (often involving scanned/faxed docum…
> First, from incorporation to issuance of the EV certificate, I spent less than an hour of my time and about $177. $100 of this was to incorporate the company, and $77 was for the certificate. It took about 48 hours from incorporation to the issuance of the certificate.
> The primary point raised by advocates of extended validation is that obtaining EV certificates would leave behind a signifigant paper trail of the bad actor's identity. However, there is minimal individual identity verification in the process. Dun & Bradstreet1 is the only entity who attempted to verify my identity, and did so with a few trivial identity verification questions. Purchasing identities with answers to common verification questions is neither hard nor expensive.
> Otherwise, there was no attempt at identity verification from the state of Kentucky or the registered agent I used in the process. This is typical of company formation in the United States.
Given the use of a registered agent, and given that registered agents are a pretty common thing, I don't think that anything is actually being burned here, unless you want to say that any registered agent who incorporates a phishing company gets all their other companies banned. Which, like the CASC's "You can't have EV if you haven't existed for 18 months" suggestion, will technically work at the cost of making EV useless.
Also, a lot of attacks don't care that they're burning credentials anyway. You don't need to spoof MyEtherWallet more than once to walk off with hundreds of thousands in Ethereum. You don't need to spoof the Washington Post more than once to spread fake news 48 hours before a presidential election.