So, your connection to _qhtn.org may be secure, but it may not be this _qhtn you're exchanging data with. Traditional CAs claim to do some sort of ID verification.
EDIT: I am very wrong.
So, your connection to _qhtn.org may be secure, but it may not be this _qhtn you're exchanging data with. Traditional CAs claim to do some sort of ID verification.
EDIT: I am very wrong.
DVs are available from almost every CA. They're popular because they involve no paper checks which makes them cheap and fast. You don't need a company to get one, like you do with OV and EV.
DV should give some level of confidence that you're connecting with the owner of the domain name. CAs should make you go through a process that only a domain's controller could complete.
So I can't get a DV for paypal.com but I can get one for olipaypal.com if I own that domain. I can't get an OV or EV for either domain showing Paypal as the company unless I somehow manage to register that as a company name somewhere. Possible? Probably.
[1] http://www.netcraft.com/internet-data-mining/ssl-survey/