4 ms·
Now, I don't disagree with what you are saying, but the simple truth is that people didn't do this anyways. In fact, the one time I tried to explain to my grand
by 7steps2much 5y ago
Now, I don't disagree with what you are saying, but the simple truth is that people didn't do this anyways. In fact, the one time I tried to explain to my grandmother how this whole thing works she then told me:
I just need to type in that address by hand and make sure I don't mistype right?
She then proceeded to inform me that her bank person had made sure she knows what an internet address is and that chase.com is in fact not chase.com.scammer.ru
EV certs are not unique. If I were to want a cert saying that it is issued to Chase Inc. then I would just have to found a company called Chase.
Domain names however are unique.
EV certs were always an ugly hack and quite frankly a bad one as well. I think LE handing out certs just for encryption is good. Users should not associated encryption with identity verification.
If you want something like that then the easy way would be to not use CA at all, but banking apps that connect to a server with only certain certs. Or maybe hand out Yubikeys that perform a handshake with the website.
But relying on EV certs is like relying on the fact that a certain envelope has a logo on it.
- nailer 5y ago> If I were to want a cert saying that it is issued to Chase Inc. then I would just have to found a company called Chase. In the US duplicate business name are indeed an issue. Trademarks are however federally unique and could be used to solve this problem. > (my grandma) then proceeded to inform me that her bank person had made sure she knows what an internet address is and that chase.com is in fact not chase.com.scammer.ru Wow. That’s better than most programmers. Did everyone clap?