2 ms·
But unless clients or humans do anything in response to the extra OV information, or in response to a lack of the extra OV information, that information has no
by konklone 10y ago
But unless clients or humans do anything in response to the extra OV information, or in response to a lack of the extra OV information, that information has no security value.
No browsers do anything with OV data unless humans manually take action to examine the certificate. So I'm comfortable saying they offer negligible security value.
- kelnos 10y agoI think if a browser said "hey, this site used to have an OV cert, but now has a DV cert", and explained why that could be bad, that could be useful, though many non-technical users would probably not get the distinction. Sure, they don't do that now, but UI/UX around TLS has been improving a lot over the past few years. (Certificate Patrol's noting of the reverse is a little silly though; why would you flag a change that denotes an increase in security...?)