LWN.net Logo

Extended validation certificates

Extended validation certificates

Posted Nov 2, 2006 22:07 UTC (Thu) by martinfick (subscriber, #4455)
In reply to: Extended validation certificates by gerv
Parent article: Extended validation certificates

Ahh, the VIP falacy again. Make something a VIP and it is more valuable to fake. You say that it won't be worth it to fakes because it is too expensive. Doesn't that imply that the supposed added trustworthiness of this systems instantly makes it more worthwhile to fake, making bigger phishing expeditions possible?


(Log in to post comments)

Extended validation certificates

Posted Nov 2, 2006 22:17 UTC (Thu) by gerv (subscriber, #3376) [Link]

Yes, EV will be a bigger target if consumers start to trust it (as we hope they will). Then we'll see if the vetting guidelines we've come up with are strong enough. If they aren't, the Forum will revise them until they are.

In the past, there was no standard for CA vetting and so no way to raise standards if there were problems. Now we have a baseline. We hope it's good enough as-is (with input from the community which is coming now) but, if it turns out not to be, we can change it and the CAs will strengthen their vetting.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds