4 ms·
The article doesn't say that you can't stay in business using DV certs, so that seems irrelevant. The article says that "Secure" falsely communicates to the ave
by parenthephobia 9y ago
The article doesn't say that you can't stay in business using DV certs, so that seems irrelevant. The article says that "Secure" falsely communicates to the average user the sense that it is safe to proceed without caution, and indeed was specifically chosen for that reason.
That's hardly controversial, I would have thought. If it's true, it's true whether or not the person telling you it sells EV certs.
Unwary PayPal users are regularly phished even though PayPal have EV certs because the average user doesn't know that authentic PayPal websites should always say "PayPal, Inc. [US]" in the address bar, and aren't concerned when the address bar says Secure instead.
I think the problem really is that we want users to be "safe" on the Internet without them having to learn anything, and the Internet just isn't there yet, and quite possibly never will be.
It's like trying to design a gun you can't shoot yourself in the foot with, because people won't put up with being taught gun-safety.
I do think we could benefit from new Internet users being made, probably by their browsers, to take a short training course in the basic aspects of what encryption really guarantees on the web, how recognise malicious websites, and the like.