3 ms·
Ordinary SSL certificates only require you to have access to domain's DNS records, or to the server where they point to. They only prevent MITM attacks, and you
by waterbomb0 8y ago
Ordinary SSL certificates only require you to have access to domain's DNS records, or to the server where they point to. They only prevent MITM attacks, and you cannot really know who is behind some domain.
With the EV certs, you can be assured that it actually belongs to the company it claims to belong. If I see "PayPal, Inc. (US)" in the address bar, I'm sure I'm accessing the correct server. However, I didn't really know that business names are not unique between different US states, but I assume this is not the case for other countries.
The issue with EV certs is how they are presented in the browser, since they are indistinguishable to the ordinary certs, at least to the majority of the users.
- ubernostrum 8y agoHowever, I didn't really know that business names are not unique between different US states, but I assume this is not the case for other countries. Uniqueness of business entity names is something you should never ever assume or rely on.