3 ms·
You've got a bit of circular reasoning here. Phishers weren't using SSL before HTTPS Everywhere much because it didn't matter. Most users (and in particular, u
by eridius 7y ago
You've got a bit of circular reasoning here.
Phishers weren't using SSL before HTTPS Everywhere much because it didn't matter. Most users (and in particular, unsophisticated users that are more likely to fall for phishing attempts) who type in passwords by hand aren't going to notice the lack of a padlock. We needed HTTPS Everywhere before browsers could meaningfully penalize the HTTP experience, otherwise they'd be penalizing the majority of sites on the internet. And we can't have HTTPS Everywhere unless SSL certificates are easy to obtain.
Which is to say, the fact that phishers can obtain a LE cert today for their phishing site and therefore not have the "Not Secure" indicator is not meaningfully different from the old days where they'd use HTTP and not have the small green padlock that most people don't notice.