5 ms·
Perhaps it's neat for you, I just found out that our newly issued EV certificate status is being revoked in the next build of Chrome, so our expensive EV certif
by Shanea93 10y ago
Perhaps it's neat for you, I just found out that our newly issued EV certificate status is being revoked in the next build of Chrome, so our expensive EV certificates may as well be $5 StartSSL certificates.
I imagine that there will be a lot of angry customers asking for refunds from Symantec/Verisign for certificates already issued which no longer conform to the offered product.
- ChristianBundy 10y agoHow recently did you renew? This has been in the works for over two years,I'm surprised that anyone is still giving them business.
- hannob 10y agoI for one find it totally neat that people realize their expensive EV cert was a waste of money. Although that was true before, too. EV certs are a waste of money, the only thing they do is show a green bar. They don't improve security.
- Shanea93 10y agoAbsolutely, I totally get that, it's worth mentioning that we take our TLS implementation seriously (HSTS, no TLS1.0, etc) and score an A+ on SSLLabs test: http://i.imgur.com/QbH4YZS.png http://i.imgur.com/QbH4YZS.png The green bar with our company name in it translated in to a measurable conversion increase week for week from guest checkouts, so saying it's a waste of money isn't strictly true in our case.
- dan1234 10y agoIt proves (if the issuer has done their job) that the organisation requesting the certificate has been properly vetted, so you’re more likely to be doing business with the right website.
- zorpner 10y agoAs the neighbor comment points out, EV validation is absolutely not a waste of money. I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. They don't improve security -- that is true.
- ceejayoz 10y ago> I've been part of A/B testing on most aspects of domain security and it's arguably one of the best ROIs out there for e-commerce sites. That's a bit hard to reconcile with the fact that Amazon.com can't be bothered to get one.
- the8472 10y agoamazon has brand recognition, they don't need to assuage people's semi-conscious perception of site trustworthyness.
- rcthompson 10y agoMost outliers are hard to reconcile with the mean.
- msbarnett 10y agoAmazon as a brand already has the trust of visitors to the site, through sheer pervasiveness in our culture. Non-household name eCommerce sites benefit significantly from quality signals like the EV bar, however.
- therealmarv 10y agoWow, that's interesting. Would you mind share numbers like percentage of A and B group?
- prdonahue 10y agoSo you're serving an EV vs. DV/OV some random % of the time for same site and measuring conversions? Mind sharing the data?
- aianus 10y agoThey can improve security. We used to pin the EV roots of a couple CAs that we trusted in our mobile apps and in the browser via hpkp. This protected against someone tricking or coercing a lesser CA into issuing a DV cert and MITMing us.
- gcp 10y agoI don't understand how EV vs DV factors into certificate pinning here.
- aianus 10y agoIf we had a DV cert and pinned the DV root then the barrier for an attacker is a lot lower. They just need to jack our DNS and get their own automated DV cert issued quick.
- theptip 10y agoWhy does EV make a difference here? Can't you pin an intermediate or root cert from your CA of choice and avoid other CAs issuing end certs for your domain just as well?
- nailer 10y agoI think the idea here is that they're not trying to prevent other CAs from issuing end certs, they're trying to only allow certs for their domain - from any CA on their short list - if the owner of the cert has been through Extended Validation.
- tialaramex 10y agoOf course, this only works if the CA _actually_ makes sure they don't use the root you pinned for DV issuance. Just because it says "Ultra Great EV root" in the CN doesn't provide you that security, and it won't count as mis-issuance so long as the DV certificate doesn't have an EV policy OID baked into it. If we'd asked in 2015, Symantec would probably have pointed us to CrossCert's CPS which said they only use certain Symantec roots. In fact Symantec had no mechanism in place enforcing that, CrossCert could and did issue from any Symantec root, whether it was on the list or not. So, if you chose a root thinking "I don't trust CrossCert, but they don't use this root so it's fine", oops, too bad.
- nailer 10y agoEV certificates have the same level of confidentiality and integrity as DV certs, but they have different authentication - specifically, they tie the certificate to a legal entity rather than a domain name. ie. https://paypal.com-customerservice.ru vs PayPal Inc [US] | https://paypal.com I run https://certsimple.com https://certsimple.com. We sell EV certs. But you can verify the above pretty easily by checking out the EV guidelines, the additional requirements that apply only to EV certs (https://cabforum.org/extended-validation/ https://cabforum.org/extended-validation/). You can also see the difference with openssl pretty easily: Here is a DV cert: openssl x509 -in domain-validated-example.com.crt -noout -text | grep Subject OU=Domain Control Validated CN=example.com DNS:example.com Here is an EV cert: openssl x509 -in extended-validated-example.com.crt -noout -text | grep Subject: jurisdictionOfIncorporationCountryName=GB businessCategory=Private Organization serialNumber=09378892 C=GB ST=City of London L=London O=example Limited CN=example.com DNS:example.com -
- Shanea93 10y agoYour pricing is very reasonable and I've just placed your website at the top of my to-do list tomorrow morning, thanks for posting.
- nailer 10y agoThanks! We're actually about the middle of the road price wise, our main thing is tech: the EV process can be pretty painful, our role is to speed it it up and make it easier. We start checking against government directories in 63 countries prior to payment, use webcrypto in supported browsers to quickly generate CSRs, make instant-paste openssl / windows scripts to make an ECC or RSA keypair quickly if you prefer to make keys on your own servers, we have a LOT of country specific logic, a meta directory of 'Qualified Independent Information Sources' to handle that part of the EV requirements, we validate in realtime and a bunch of other stuff to save you time and effort - https://certsimple.com/about https://certsimple.com/about. There's cheaper options around, but we only do EV and we're the best at it.
- galdosdi 10y agoWhat? Of course they improve security. They reduce the risk the user has accidentally navigated to a squatted typo-domain registered by an attacker (or the correct domain, but the registration somehow accidentally expired and was reregistered by an attacker)
- deleted 10y ago[deleted]
- beedogs 10y agoShould've gone with a better vendor. Symantec has been a known bad actor in this field for years now.