logoalt Hacker News

realitykinglast Tuesday at 9:14 PM2 repliesview on HN

EV certs also showed the legal name of the company that requested the certificate - that was an advantage.


Replies

duskwufflast Tuesday at 10:26 PM

Which would have made sense if company names were unique - which they aren't. See e.g. https://groups.google.com/g/mozilla.dev.security.policy/c/Nj... for an example of how this was abused.

show 1 reply
crotelast Tuesday at 11:38 PM

The problem is that people wrongly believe that company names are unique. In reality you're just some paperwork and a token registration fee away from a name clash.

If anything, it's a disadvantage. People are going to be less cautious about things like the website's domain name if they see a familiar-sounding company name in that green bar. "stripe-payment.com" instead of "stripe.com"? Well, the EV says "Stripe, Inc.", so surely you're on the right website and it is totally safe to enter your credentials...

show 1 reply