4 ms·
Agreed, that's exactly the purpose of EV. The problem is that the user has to know to look for EV, check it's present and check that it says "Apple Inc." which
by Scott_Helme_ 9y ago
Agreed, that's exactly the purpose of EV. The problem is that the user has to know to look for EV, check it's present and check that it says "Apple Inc." which is a lot of things to expect of the user! There are also lots of scenarios that I outlined in my article where you would never see an EV indicator because of your browser, platform or TLS interception taking place. Not only do we burden the user but the indicator is also unreliable.
If apple.co was doing nasty things it'd also be blocked pretty quickly with things like Safe Browsing which is great.
- nailer 9y agoA lot of your arguments re: EV are dead on, but they're not to do with the concept of verifying certificate owners (EV), but rather browser implementation issues. Eg, you see an improtant update to a ToS you need to accept or a service you use will be stopped. You click the link, log in, and your browser says... For DV: > This is the first time you've visited this site. The owner has been verified as amazon.com or, for EV: > This is the first tim you've visited this site. The owner has been verified as Apple, Inc. for a DV phishing cert > This is the first tim you've visited this site. The owner has been verified as www.google.com-swag.ph Unfortunately browsers don't make certificate information available to users, and are uninterested in whether users understand what they're connecting to (https://certsimple.com/blog/browser-security-indicators https://certsimple.com/blog/browser-security-indicators). The same thing applies to mobile Chrome poor identity display compared to mobile Safari. This doesn't mean we should stop verifying pubkeys with EV. It means browsers should improve their UI or let others do so.
- Scott_Helme_ 9y agoHow is the user supposed to know what to verify in the EV indicator though? If the user is expected to know that the EV indicator should contain "Apple Inc.", why can't we just expect them to know the address should be apple.com instead, what's the difference? I can't seem to get away from two key things that put me off and they are requiring the user to have some pre-existing knowledge of the name of the legal entity and then having to manually notice and verify that information on each page. Let me list a couple of scenarios to see if I can better articulate my thoughts. 1) The user wants to buy something from ACME Corp so they search for them on Google and find acme-corp.com listed as their site. The user visits the site and sees in the EV indicator that this domain is indeed owned and verified as ACME Corp [US], the company they wanted to interact with. In this scenario the user is required to have pre-existing knowledge of who they wish to visit the site of and then manually verify that information. 2) A user is browsing the web and finds a product on a website that they want to buy. They check the address bar for https and also notice an EV indicator that says Bargain Central [UK]. Without existing knowledge of who the company is, what value does the EV indicator provide? Maybe I'm missing something, and please do feel free to point out some other user scenarios, but #1 requires the user to have existing knowledge which is a pretty big burden to place on them. I can't really think up a scenario these days where someone would tell you a company name to buy something form or visit online but not their website address. With #2 it seems to provide no value because the user has no reference as to who that company is. Given the information in the EV indicator the user would need to go and lookup information about the company somewhere else? We certainly can't assume that they're trustworthy just because they have an EV cert! I honestly don't think the biggest problem with EV is browser UI. As I detailed in the linked article there are many scenarios when EV will never show because of AV/interception/proxies/etc and there's nothing that can be done about that. Even if all browsers had a consistent UI, my biggest concerns would still remain what they are now.
- nailer 9y ago> How is the user supposed to know what to verify in the EV indicator though? In the proposal, the user doesn't know anything about the EV indicator. The browser simply prominently shows the user the highest level of identity information on first POST (maybe with a two week delay on fresh browsers). Do you trust: - amazon.com - Apple, Inc. (United States) - apple.com-yolo.swag.ru The proposal is particularly neat as it doesn't discriminate against well known domains with DV, just shows users what the cert proves at the time they most need to know. I could make this in a day, and prove it improves end user security, if Ryan (or anyone else) would let me. (I'll address your scenarios in another comment, just wanted to clarify the identify-on-first-POST proposal first)
- Scott_Helme_ 9y agoI'm not opposed to your proposal but I would have some hesitation about an intersitial like that. The example works well with Amazon and Apple but what about: - some-company.com - Other Company [United Kingdom] - some-company.com-fake.uk Unless you already know you wanted Other Company [UK] (pre-existing knowledge) the EV indicator really doesn't help.
- nailer 9y agoThanks. Again there's no explicit EV indicator being proposed in identify-on-first-POST: just a single UI with the highest amount of info known about the site's identiy. Re your examples: 1. > This is the first time you've visited this site. The owner has been verified as some-company.com "OK. Have I heard of these people before? The dash is a bit weird. Not bad, not good - which is reasonable for site that isn't telling me anything." 2. > This is the first time you've visited this site. The owner has been verified as Other Company [United Kingdom] "OK cool. I live in the UK and I know who is handling my data." 3. > This is the first time you've visited this site. The owner has been verified as some-company.com-fake.uk "Euw gross. I'm out of here."
- Scott_Helme_ 9y ago
- stephenr 9y ago> Unfortunately browsers don't make certificate information available to users, and are uninterested in whether users understand what they're connecting to Sure, if by "Browsers" you mean "the browser made by the Ad Network company that has a vested interest in people using web based computing for everything they do, regardless of security concerns". My browser (Safari) shows me the domain I'm connected to for DV, and the verified organisation name for EV, and the certificate details are a click away in either case. If Chrome doesn't provide some of that information, thats a fault against Chrome, not the concept of Certificates.
- stephenr 9y ago> If apple.co was doing nasty things it'd also be blocked pretty quickly with things like Safe Browsing which is great. Safe Browsing covers malware, and.. maybe phishing? There are plenty of other things bad actors can do while impersonating well known sites.