Of course, the non-internet version of a CA, credit rating agencies, do not behave any better with the trust given to them by the public.
Maybe the creators of the Bitcoin alt coin "namecoin" had the right idea.
Of course, the non-internet version of a CA, credit rating agencies, do not behave any better with the trust given to them by the public.
Maybe the creators of the Bitcoin alt coin "namecoin" had the right idea.
As the original article points out, you can perform these kinds of attacks with any address by setting up sub domains ("https://www.paypal.com.safe.com" looks pretty similar to "https://www.paypal.com" to most users).
I personally think this is an issue with the browser UI/UX as it currently stands. "Secure" sends the wrong message to your average user. I would like to see something like the prominent display of the second/third level domain at the top of every browser tab (depending on the TLD). i.e. "ycombinator.com", "paypal.com", etc.
It's very easy: get the browser vendors to remove them from the root store. It's exceedingly effective. The "problem" is that the browser vendors seem to agree that CAs shouldn't be content watchdogs.
Did you read the linked position paper from LetsEncrypt?
So if a CA offers a certificate to a legitimate wordpress site, which then proceeds to let itself get hacked and host a phishing page, that CA now has to pay a fine?