logoalt Hacker News

unethical_banyesterday at 8:33 PM2 repliesview on HN

EV validated not only that a domain was under control of the server requesting the cert, but that the domain was under control of the entity claiming it.

I kind of wish they still had it, and I kind of wish browsers indicated that a cert was signed by a global CA (real cert store trusted by the browsers) or an aftermarket CA, so people can see that their stuff is being decrypted by their company.


Replies

tadfisheryesterday at 9:12 PM

Problem is, I can easily set up a company and get an EV cert for "FooBar Technologies, LLC" and phish customers looking for "FooBar Incorporated" or "International FooBar Corp.". Approximately zero users know the actual entity name of the real FooBar.

show 2 replies
arccyyesterday at 8:35 PM

you can find quite of few examples online that the entity check wasn't all that strict...