Not saying that's a solution, but it mitigates the problem somewhat.
Not saying that's a solution, but it mitigates the problem somewhat.
I know certificates must be revoked if the private key leaks (e.g. Heartbleed), but who is policing certificate use? Is there any place to send complaints? Can I email StartSSL or VeriSign and ask them to revoke faceb00k.com?
I think so, yes. I don't have any direct evidence to back this, but my intuition is yes, they would contact the intermediary cert issuer and request the certificate be revoked due to the fraud (assuming Verisign or StartSSL were in the trust chain of the cert).
Check out Trustico's website [0], where they say "Your domain name may be blacklisted and internet users will be wary to transact with your web site."