4 ms·
This is scary, especially safari displaying only the name of the company and not the domain name. I don't see how we could provide a totally safe network of si
by cdancette 9y ago
This is scary, especially safari displaying only the name of the company and not the domain name.
I don't see how we could provide a totally safe network of sites (where you can trust the identity of every site you're visiting), without having a "safe internet" where all the sites are known in advance and you can't leave this walled internet. But I really don't like the idea.
Maybe something like keybase could help, where sites could link their identity to social network accounts (twitter, Facebook, GitHub) or other websites.. and the browser would verify those connections (but it still faces a UI challenge)
- samwillis 9y agoKeybase actually already allow validation of a domain name with dns record. If they could add validation of an tls (ssl) certificate and provide a browser extension that added their own indicator to the toolbar to validate that the domain is owned and secured by the correct entity that would work well.
- zaarn 9y agoThere is a different use case though. Keybase already has your Public Key so to prove you own a domain it is sufficient to put a signature up and available in DNS to validate this claim. An attacker does not have this validation signature and can thusly not arbitrarily sign sites as you. I don't see how keybase would help for a Certificate Validation, especially since Keybase makes no actual attempts at indentifying you (that is a problem of your social circle on keybase)
- paultopia 9y agoIt seems to me---though I could be wrong---that it's only a small subset of sites that are the primary high-value targets for phishing attempts. Could browser vendors make a significant improvement simply by keeping a list of major financial institutions, government agencies, huge employers, etc. and warning users before going to a site with a URL or certificate identity similar to those entities?
- cdancette 9y agoI think the hard part is how to tell if some site is "similar" to a sensitive site. Do you check just the owner ? (like in the example, but that would prevent any other company named stripe to own an EV certificate) Or do you check if the domain is similar to another one? This is a very hard problem. Maybe the similar name approach could work if it displayed just a warning to the user when he visited a site owned by someone with a similar name to a sensitive site.
- paultopia 9y agoThat's what I was thinking of. A simple "hey, just so you know, this website has a pretty small edit distance from "paypal.com" (or ditto with certificate owner names). If you're trying to go to the big important financial institution that ain't it, but otherwise click here to carry on." Not perfect, obvs, but would that be an improvement?
- cdancette 9y agoAnd even sometimes, you can have totally unrelated domains, but the site that looked exactly like PayPal, and people don't look at the domain (sometimes the site doesn't even have a certificate).. Hard to find a solution to this scam problem
- yorwba 9y agoIf you want to throw machine learning at it, the browser could try to predict what site the user thinks they are on, and highlight any discrepancies. The data collection necessary to get an accurate model would however be quite invasive, so I'm not quite sure whether I'd use a browser with that ability. Maybe just having visual fingerprints of the most visited sites and serving them as a static model would be enough.
- cdancette 9y agoYeah, I guess this could work, like the spam filter in your mailbox.