"Why are you typing your password on faceb00k.com?"
"It has a green padlock, it's safe."
I don't have any suggestions for this problem, but I think it should be acknowledged at least.
"Why are you typing your password on faceb00k.com?"
"It has a green padlock, it's safe."
I don't have any suggestions for this problem, but I think it should be acknowledged at least.
Not saying that's a solution, but it mitigates the problem somewhat.
I know certificates must be revoked if the private key leaks (e.g. Heartbleed), but who is policing certificate use? Is there any place to send complaints? Can I email StartSSL or VeriSign and ask them to revoke faceb00k.com?
I think so, yes. I don't have any direct evidence to back this, but my intuition is yes, they would contact the intermediary cert issuer and request the certificate be revoked due to the fraud (assuming Verisign or StartSSL were in the trust chain of the cert).
Check out Trustico's website [0], where they say "Your domain name may be blacklisted and internet users will be wary to transact with your web site."