|
|
Log in / Subscribe / Register

Ever-growing CRL?

Ever-growing CRL?

Posted Dec 9, 2024 21:48 UTC (Mon) by NYKevin (subscriber, #129325)
In reply to: Ever-growing CRL? by tialaramex
Parent article: Let's Encrypt sets date for ending OCSP support

IIRC there was also someone who created a business called "Identity Verified" and then got an EV certificate for it... which caused the words "Identity Verified" to appear next to (or in the case of mobile Safari, *in place of*) the URL bar. Now, if you're familiar with how certificates work, you can probably figure out that the blanket phrase "Identity Verified" is not a promise the browser can plausibly make, even if you don't know the details of what's supposed to be displayed there. But the average end user should not be expected to understand how the web's PKI works (or fails to work). From their perspective, if the browser is confidently displaying a green UI that says "Identity Verified," well, then it must be OK, right?

And this leads us to the broader problem with EV: You are allowing third parties to display (effectively) arbitrary text in the browser's trusted UI, in green and right next to a lock symbol, with the intent that users accept that text at face value. There are probably a thousand different kinds of mischief that attackers can make with that. The only reason they mostly didn't bother is because, back when EV was still a thing, you didn't even need HTTPS for phishing in the first place since so much of the web was still on plain HTTP.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds