9 ms·
Are EV certificates worth the paper they're written on?
- pgl 9y agoPretty thorough examination the pros and cons of Extended Validation SSL Certificates, with some good discussion in the comments.
- jorgec 9y agoMost companies don't care about the EV, aka the GREEN BAR. For example, Paypal and Apple care but not Google, Amazon or Microsoft. So, its not a matter of costs but its usability that its practically NIL. Even Ycombinator is not using it. As a developer, i am found that practically all customers don't care about the URL, in fact, most customer don't see the url at all.
- BillinghamJ 9y agoThe primary benefit I have found is for pinning/CA whitelisting purposes. All EV certs must have publicly searchable CT records, and go through reasonably complex validation processes involving some manual human validation processes, in addition to the usual checks. This means that: 1. The barrier to getting an EV cert is higher - and the probability of a misissuance is lower. 2. If a misissuance does occur, it should be very easy to find out - by regularly/automatically searching CT logs. If you choose two or three CAs whose EV programs you trust, you can pin against those CAs’ EV roots in your applications (e.g. a mobile app published by your company). This is an effective process to reduce the risk of MITMs, and even continues to work as the CA changes intermediates etc (assuming they have separate roots for EV). There isn’t a whole lot of benefit in browsers, unless you have preloaded pinned certificates there too (which many major sites do). Also, as an aside, if anyone is looking for EV certs, I have always wholeheartedly recommended CertSimple. They’re very quick, aren’t too expensive, and have good support. The certs are issued by DigiCert. We use them for https://cuvva.com https://cuvva.com
- rocqua 9y agoSure, if I see an EV cert, I trust that cert slightly more. However, unless I expect an EV cert and happen to check, there is no downside to having a DV cert. If you are going to pin your apps to a CA, you have quite a few other options. For example, you could cross-sign all your certs by your own root CA cert and pin to that in addition to pinning to the other CA. At this point, you don't need to trust the CA as long as you trust your own root cert.
- BillinghamJ 9y agoI didn’t make any reference to any visual/user benefits/trust from EV certs. If you’re going to do cross-signing, then you do need to essentially operate your own root program - assuming you want to keep your own root secure. You’ll also then presumably need to serve an additional cert (or two, if you’re keeping your own root offline) in the intermediate chain so it can be validated by the client.
- Scott_Helme_ 9y agoIn April next year we will have the CT requirement for all certificates so EV will lose an edge there. For the pinning in a mobile app, would you still depend on the PKI or not just pin against your own private CA/certificates?
- BillinghamJ 9y agoOur mobile apps use the same endpoints/hostnames as our public API, so fairly important for it to be publicly trusted. I do still think the barrier to entry aspect of EVs will always be very helpful. In a world where you can get a DV cert in under a second (from LetsEncrypt), if your DNS or domain registration was to be compromised, you’d have no MITM protection at all until you managed to get it revoked - which is likely to take days. It’d almost be helpful to have a system where certs have to be requested (publicly on CT records) a week in advance or something, so issuance can be protested if something like the above did happen.
- Theodores 9y agoGreen bar EV caught me by surprise the other day, I did not know what it was and even checked the likes of Google to see if everyone else had one. This did actually take me away from the checkout of the website I was on, so it kind of broke 'Don't make me think' for me in that instance.
- nailer 9y agoFYI microsoft.com has an EV certificate. Google.com has a OV certificate, where identity is matched to google.com but this isn't shown in the browser. it's a similar level of verification as EV but without the UI. Note Google have a lot of user generated content (eg, AMP sites) hosted on google.com YC's website isn't an example of great tech. (See bio/disclosure in my other comment)
- deleted 9y ago[deleted]
- the-dude 9y agoWorked for payment provider : at one point customers did not trust our checkout page because it was not EV ( it was plain SSL ). For financial stuff it is apparently expected ( NL ).
- rocqua 9y agoHow many customers? And how technically apt are they? I know my grandparents never see the EV certs, because their AV does TLS termination (I tried to talk my uncle out of it, but he really trusts AV). I don't see anyone I know caring about an EV cert missing for a payment provider. The only exception I can think of would be for big national banks (Rabobank, ING, etc) for those it might be weird not to see EV because all the others have it.
- the-dude 9y agoIt was not mollie.nl, but similar.
- rocqua 9y agoI can see that being a weird edge case. Especially because mollie is often used by smaller sites. The first few times I saw the name, it felt rather sketchy that I was paying to mollie rather than whatever business I was buying from.
- thinkMOAR 9y ago[company name redacted]
- deleted 9y ago[deleted]
- thinkMOAR 9y agoI wouldn't be surprised if you got fired. Disclosing lots of information, even i think your ex employer wouldn't really like it if you disclosed that without EV sales took a tumble. Generally upsets customers that you ruined their potential sales. If you call me posting the company name a dox, perhaps don't share so much information online. My grandmom could have figured this out. </let the minus votes flow in>
- enord 9y agoTop 10 sites are not using EV because they don't wan't to meet the expectations of EV-level trust. If twitter compromises your account details, you can change your passwords. If your (E-validated) electronic banking service compromises your account details, you can sue. EV is laborious for social reasons (and some technical reasons ofcourse, nobody likes ASN1 extensions etc.), your effort to secure and validate a service is proportional to your stake in the transaction.
- pfg 9y agoI'm not sure I follow, why does a site's use of Extended Validation affect your ability to sue them? Or do you mean it's a psychological thing - "If our site uses EV, we're more likely to get sued"?
- enord 9y agoWell it's expected in contexts where legal responsibilities are defined and widely understood (or misunderstood, depending) and also because it's literally the reason they exist. To quote wikipedia: >An Extended Validation Certificate (EV) is a certificate used for HTTPS websites and software that proves the legal entity controlling the website or software package.
- pfg 9y agoI still don't quite follow. You were talking about adoption among top 10 sites - is your argument that Twitter is not using an EV certificate[1] because a judge might say something along the lines of "That's all great but how do I know this twitter dot com thing is actually a site operated by Twitter, Inc? They're not using EV!" if some users sues them over a data breach? [1]: Not really important for this discussion, but slightly relevant: For some reason Twitter uses both EV and non-EV certificates depending on geolocation.
- galobtter 9y agoYeah I don't think google not using a EV certificate really changes whether I can sue them
- zokier 9y agoWhile some of the criticism against EV might be valid, I don't see many good alternatives. Should we just collectively abandon any hope for better-than-DV level of security, is that really a desirable outcome?
- Ajedi32 9y agoWhat kind of alternative are you looking for? DV security is already quite good, and it's getting better with new measures like Certificate Transparency.
- stephenr 9y agoDv does nothing to tell you who operates the site. What if someone else had managed to register Apple.co and started using it nefarioualy? Having an ev cert we can see if a site is actually an Apple Inc site or not. There is more to tls/https than encrypting the tunnel.
- Scott_Helme_ 9y agoAgreed, that's exactly the purpose of EV. The problem is that the user has to know to look for EV, check it's present and check that it says "Apple Inc." which is a lot of things to expect of the user! There are also lots of scenarios that I outlined in my article where you would never see an EV indicator because of your browser, platform or TLS interception taking place. Not only do we burden the user but the indicator is also unreliable. If apple.co was doing nasty things it'd also be blocked pretty quickly with things like Safe Browsing which is great.
- nailer 9y agoA lot of your arguments re: EV are dead on, but they're not to do with the concept of verifying certificate owners (EV), but rather browser implementation issues. Eg, you see an improtant update to a ToS you need to accept or a service you use will be stopped. You click the link, log in, and your browser says... For DV: > This is the first time you've visited this site. The owner has been verified as amazon.com or, for EV: > This is the first tim you've visited this site. The owner has been verified as Apple, Inc. for a DV phishing cert > This is the first tim you've visited this site. The owner has been verified as www.google.com-swag.ph Unfortunately browsers don't make certificate information available to users, and are uninterested in whether users understand what they're connecting to (https://certsimple.com/blog/browser-security-indicators https://certsimple.com/blog/browser-security-indicators). The same thing applies to mobile Chrome poor identity display compared to mobile Safari. This doesn't mean we should stop verifying pubkeys with EV. It means browsers should improve their UI or let others do so.
- danpalmer 9y agoWe've found (anecdotally) that our customers care about the "green bar", although this isn't something we've A/B tested yet. Note: we're online retail, I don't think it matters for SaaS anywhere near as much.
- deleted 9y ago[deleted]
- nlh 9y agoI would argue that the top 10 sites aren’t using EV because they don’t need to use EV, precisely because they’re top 10 sites. If I’m visiting Amazon, I’m pretty sure that I’m getting the security I’m expecting simply by seeing Amazon’s domain, the pages I recognize, and some semblance of SSL. It’s the lesser-known sites, I think, where this sort of “trust” (for some version of trust) matters more — random-ecommerce-site.com doesn’t have the brand value or trust factor of Amazon, so they need every (perceived) advantage they can get, EV being one.
- Scott_Helme_ 9y agoI do touch on that point in the article but the numbers show that larger sites are more likely to use EV and smaller sites are less likely to use it. The figures seem to go against the logical assumption. I grabbed the figures and published them because I thought as you do.
- nailer 9y agoDisclosure: I work for https://certsimple.com https://certsimple.com, we're a startup that focuses on making the EV verification process faster and less painful than other verification methods. There's a few different reasons people use EV. Most are similar to verification on other platforms, eg AirBnB, Whatsapp, Facebook (Twitter is unique as that has additional requirements beying identity verification). - You're a smaller company, handing sensitive information, and you want people to know there's a real legal entity behind the website they're giving it to. Eg fintech startups and new dating sites. - You're a company that has resellers, counterfeiters or other non official sites and want to distinguish you're the actual brand. Typically fashion retail is the buggest demand here. - You simply want to match a public key to a real world identity, just like any other cryptosystem, in the same way that the fields in the CSR were checked in the 90s, prior to GeoTrust inventing DV to save money in the early 2000s. Typical case here is a lot of old school sysadmins who dislike public keys that haven't actually been proven to be owned by anyone. - Phishing.
- Scirra_Tom 9y agoYour site looks great, we don't have EV on Construct.net because it's just to laborious. Will be ordering soon from you.
- baby 9y agoI've never noticed any difference between a DV and an EV certificate, and I'm working heavily in this field. The difference is useless unless you actively look in the address bar to see if there is a difference. Most users won't.
- Scott_Helme_ 9y agoThis is my biggest real concern with EV, we depend 100% on the user for it to have any value. I think we learnt that lesson with 'check for https in the address bar' and now we have HSTS instead.
- baby 9y ago> we depend 100% on the user for it to have any value or on the browser integration. If chrome/firefox decide to remove this distinction tomorrow, the whole business aspect of it will die.
- SAI_Peregrinus 9y agoThe only useful feature of EV certs to me is that they list the company name in the green box in the address bar. That's handy when first visiting a domain used by a company that isn't that company's main domain.
- petraeus 9y agoIts more about professional pride than anything else. What I find abut EVs is the adoption is less based on a projected increase in sales and more on if the website developer thinks its cool to have.
- mindcrime 9y agoI'm not a fan of any security mechanism that places a burden on the user And as long as people have this attitude, things will never be secure. Users are already the weakest link and excusing them from having any responsibility for their own security is not helping.
- Scott_Helme_ 9y agoI think completely the opposite. The sooner we can stop depending on the user to behave a certain way so that we can be secure, the better. We told users for years to look for a padlock and https in the address bar before entering passwords or credit card details to make sure it was encrypted. Now we have HSTS so that websites can enforce https without having to have the user manually check things and risk missing something. HSTS does not place a burden on the user, we took responsibility from the user and fixed the issue without having to involve them. That's exactly how we improve security. Clicking links in emails is another prime example. We can try to teach the user as much as we like for as long as we like but ultimately there's almost 8 billion people on Earth, so yeah, good luck on that front! Instead we can enforce policies like SPF/DKIM/DMARC to ensure the sender is genuine, check the reputation of domains linked in the body and filter them, scan attachments for malicious content, prevent execution of scripts, remove administrative privileges from the user and countless other technical measures we can deploy without even having to speak to the user once. Every time we have to ask the user to do something or to not do something, the technology has failed.
- andygambles 9y agoThere needs to be a mechanism where a site can provide its verified identity to allow the user to know exactly who they are. Not every site will need or want this but the ability should exist. At the moment EV provides this ability. If EV is not seen as the answer then we need to have something else instead. We could decouple this from HTTPS but identity is also a valid purpose of signed certificates.
- andygambles 9y ago> One of the things that I wish we had across browsers was a consistent UI so we could reliably inform users of the indicators to look for. The UI was consistent with a green address bar as agreed in the cab forum. It was Chrome that broke away from this consistency.
- BrandoElFollito 9y agoI hope let's encrypt will support someday EV, without the extended validation. Yes, without. Because this is supposed to help people, not machines, and people will never tell the difference. The ones who make the effort to understand this rainbow of colors around the url bar will not be fooled anyway (and if they are, the attack was very successful anyway). All this said, I would like to have the name of my blog next to the green lock because it looks nice. For free that is.