6 ms·
Of course, it wouldn't have helped in this case as it was the third party site that had the bad certificate. That fact is not signalled anywhere. I don't recall
by pjsg 5y ago
Of course, it wouldn't have helped in this case as it was the third party site that had the bad certificate. That fact is not signalled anywhere. I don't recall anybody (even the most ardent supporters of EV) saying that the browser should warn you if any third party references were not EV.
- nilsbunger 5y agoBut EV would give you a way to make a more secure website by hosting all the content yourself
- dboreham 5y agoThat doesn't make sense since any content loaded from a second site has the ability to compromise the first. If nobody said that, they weren't thinking hard enough. Browsers already have this kind of transitive security enforcement -- you can't load a page with TLS that then pulls JS via plaintext http.