Skip to content

Comment on Ask HN: Looking for someone to help create a trusted CAparent

Comments

It is all nonsense until money is involved and customers want to know that the advertised website actually belongs to your legal entity.

Does not help in any real way. See https://arstechnica.com/information-technology/2017/12/nope-... for an example.

There's a huge difference between "it isn't impossible to bypass" and "does not help in any real way".

The only reason to get EV certs is the supposedly "safe" green organization field. As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case? I rate that as "does not help in any real way".

As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case?

Same goes for the lock on your door. Why do you bother? Just take it off.

I never said that. The alternative isn't no lock of course. It's the free lock that's equally safe to the one with the green "this is safe" sticker that you pay a premium for.

You do realize the "lock" in this analogy that you claimed "does not help in any real way" is the EV, not the encryption?

I'm not going to continue this argument as it seems pointless. There's a reason Chrome and others moved away from prominently showing EV properties:

https://chromium.googlesource.com/chromium/src/+/HEAD/docs/s...

There most certainly was a reason, just not your reason (circumvention). Read the page you linked to. It literally says "users did not notice it", "users do not notice their absence", "users do not react as intended to positive or neutral security UI". It was user-focused. Not attacker-focused.

But I do agree it's pointless to keep continuing this.

I pointed out that letsencrypt does not compete in the same space with some providers and I get responses from internet freedom activists who don't want to acknowledge the fact. If shit is broken and doesn't work, you don't use it to make a point, you go fix it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.