I think the Browsers should swing the axe the other direction. Indicate the website is broken when EV certificates are present. Also, indicate all websites are broken if/or when the Root-CA-trust ever be forcefully extended to include EV CA authorities, in particular state backed authorities. I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of…
I'm not sure I follow. How are EV certificates weak? They use the same cyphers and just have extra validation on the owner/domain.
To compound problems legal entity names are not required to be unique across states or countries so an EV certificate for a popular company name can be obtained in another geography and presented to the user on an attacker controlled domain.
https://www.bleepingcomputer.com/news/security/extended-vali...