3 ms·
True, but chase.com.swag.ru is not chase.com
by 7steps2much 5y ago
True, but chase.com.swag.ru is not chase.com
- jasode 5y ago>True, but chase.com.swag.ru is not chase.com Your reply is missing the point and the difficulty of the topic. Yes, _you_ know "chase.com.swag.ru" is wrong but the harder computer science question is: "How does a web browser deterministically evaluate if "chase.com.swag.ru" is not the real Chase bank the web surfer intends to reach?" In other words, the FireFox/Chrome browser doesn't have a function such as: if (ask_7steps2much_if_domain_is_real_instead_of_fake("chase.com.swag.ru")) then ... The generalized way that's been attempted is Certificate Authorities being hardcoded/whitelisted inside of browsers, etc. This helps for encryption to prevent MITM attacks but has many loopholes for identity verification. LetsEncrypt dv certs are more helpful for encryption. In contrast, something like EV certificates was trying to help with trusted identity. But it looks like EV certificates were not a UI signal used by most web surfers so Chrome/Firefox dropped the visual indicators: https://www.google.com/search?q=chrome+firefox+remove+ev+certificate https://www.google.com/search?q=chrome+firefox+remove+ev+cer...
- 5560675260 5y agoFrom user's perspective only difference between EV certificate, LetsEncrypt certificate and no certificate are couple of words hidden somewhere in browser UI and maybe an icon. You still need some level of expertise to use this info, IMO even more than you'd need to notice that "chase.com.xxx.xxx" isn't legit.
- Ajedi32 5y agoYes, and that's a problem with browser UI that should be solved. This is a major flaw I've seen with a lot of the anti-EV rhetoric that's been espoused in recent years by security experts and browser vendors. They correctly identify that the EV certificate system has major flaws, then incorrectly conclude that rather than fix those flaws, the solution is to get rid of the EV certificate system. Yes, EV certs are currently insufficient as means of identity verification. How does eliminating EV certificates solve that problem? What alternative is being proposed that would be better than EV certificates at verifying the identity of real-world entities? So far, the plan seems to be to just get rid of EV certificates and replace them with... nothing? That's not exactly helping the situation.
- nailer 5y ago> You still need some level of expertise to use this info Verification markers are common UI elements used on Instagram, Twitter, Facebook, WhatsApp and many other end user focused apps.
- 7steps2much 5y agoNow, I don't disagree with what you are saying, but the simple truth is that people didn't do this anyways. In fact, the one time I tried to explain to my grandmother how this whole thing works she then told me: I just need to type in that address by hand and make sure I don't mistype right? She then proceeded to inform me that her bank person had made sure she knows what an internet address is and that chase.com is in fact not chase.com.scammer.ru EV certs are not unique. If I were to want a cert saying that it is issued to Chase Inc. then I would just have to found a company called Chase. Domain names however are unique. EV certs were always an ugly hack and quite frankly a bad one as well. I think LE handing out certs just for encryption is good. Users should not associated encryption with identity verification. If you want something like that then the easy way would be to not use CA at all, but banking apps that connect to a server with only certain certs. Or maybe hand out Yubikeys that perform a handshake with the website. But relying on EV certs is like relying on the fact that a certain envelope has a logo on it.
- nailer 5y ago> If I were to want a cert saying that it is issued to Chase Inc. then I would just have to found a company called Chase. In the US duplicate business name are indeed an issue. Trademarks are however federally unique and could be used to solve this problem. > (my grandma) then proceeded to inform me that her bank person had made sure she knows what an internet address is and that chase.com is in fact not chase.com.scammer.ru Wow. That’s better than most programmers. Did everyone clap?