4 ms·
Would the certificate really help you here though? If we look back at most of the big data breaches over the last few years then we regularly find out long afte
by Scott_Helme_ 9y ago
Would the certificate really help you here though? If we look back at most of the big data breaches over the last few years then we regularly find out long after it's happened. It's generally a news story or a headline somewhere that xyz company was hacked.
I see what you're saying but I can't see where this would happen whilst the user has the browser window open showing EV information. If Twitter leaks your data you'd likely get an email notifying you or watch it on the news and then take action as a result of that.
- enord 9y agoIf the validation process to obtain a certificate is rigorous then you have little deniability if and when you are held accountable for any shenanigans. Where I work, if the process to obtain a certificate is rigorous enough, certain entrusted CAs can issue certificates with legal non-repudiation (legal signature) and identifying power. This is written into law. You can bet your car this will create tons of case law when GDPR lands. The EV-cert doesn't help twitter or facebook (other than making them seem more trustworthy), it doesn't provide any extra cryptographic or operational security, it helps the user better ascertain who is accountable and where when the shit inevitably hits the fan.