In case you missed the links in the article, you can also read the original research https://www.usenix.org/system/files/conference/soups2016/sou..., section 7.2 and confirm the premise of the article's title for yourself.
I use a DV cert on my personal site. CertSimple happily directs customers to LE, Heroku, AWS Cert Manager, CloudFlare and other places where you can get a cheap / free or shared DV cert for customers who just want people to encrypt data they send to their site and don't need to prove who they are.
Reasons you might want to prove who you are:
- You're handling sensitive data and want to prove there's a real company behind the site, rather than just someone who registered a domain.
- You have other people pretending to be you and want to distinguish your site from theirs.
- You have affiliates selling your product and want to show you're actually the real site.
- You're a crypto nerd and the idea of connecting to random public keys makes you boak.
- Debian/dpkg does it with key signing parties, where people hold up their passports and read out the pubkeys used to sign their packages. From https://wiki.debian.org/Keysigning :
> The people who will sign your key will need to see some form of government issued ID (passport or similar).
This is almost the same as the EV process for a sole proprietor.
- Email users who use GPG do it by publishing keys in places like keybase or university address books which confirm identity by control of other well known accounts associated with that person - eg, your Twitter handle, or university account associated with your identiy.
- SSL/TLS used to do this with phone calls, faxes and YellowPages entries, verifying that all those fields you entered into your CSR were correct, before GeoTrust invented Domain Validation to save themselves a bunch of money.
If you don't want to prove who you are, that's fine. But matching identities to pubkeys is a very, very normal part of PKI.
Cynicism is healthy. The TLS industry has historically been quite shady. Symantec was selling 'Step up' encryption certs for Internet Explorer 5.5 pre 5.5 SP1 in 2015 as a value add. Comodo tried to trademark 'Let's Encypt' for some reason that still isn't clear.
I'm quite happy for people to ignore the article I wrote, read Section 7.2 of Google's research, and verify for themselves the claim made in the title.
Then consider whether most people understand that 'Secure' means 'Secure from eavesdropping' as the quoted Google engineer suggests.
- You're handling sensitive data and want to prove
there's a real company behind the site, rather than just
someone who registered a domain.
1.) Unicode homoglyph attacks means "Goοgle Inc" looks just like "Google Inc". All browsers mitigate IDN attacks, but the way unicode strings are handled means the browser vendors have to be lucky forever, while an attacker just has to be lucky once.2.) "Widget Inc" is a different legal entity from "Widgets LLC". Is some clerk in Delaware going to care that an attacker is registering a name vaguely similar to the name of your California corp? Probably not.
3.) Chrome uses the OS cert store. As of 2016, Windows trusts 356 root certificates. Any root can sign a cert for any domain name. How much do the owners of "TUBITAK Kamu SM SSL Kok Sertifikasi Surum 1" care about your security?
4.) It costs, what, a hundred bucks to register a corp online? Easy spend if you're spearfishing a high value target. "Shell-company-as-a-service" has been a value provider of law firms for centuries.
- You have other people pretending to be you and want to
distinguish your site from theirs.
Wildcard EV certs let anyone in the world register "yourcorpname.customer-service.io", or "yourcorpname-help.com" Large corporations train users to do this, hilariously. In order to log into office 365, you visit... login.microsoftonline.com. - You're a crypto nerd and the idea of connecting to
random public keys makes you boak.
Crypto nerds don't trust the HTTPS PKI at all.- a legitimate point (2)
- Three points that indicate you don't have experience of EV (1 - you would have to prove you're legally 'Google Inc' with a homoglyph to a CA, which would be difficult, 3 as vtlynch mentioned, Timbuktu CA is unlikely to issue EV certs and if it does so would be required to be audited on how well it meets the EV for CAs requirements and 4, wildcards are expressly forbidden for EV).
- some which are against PKI, which is great but even more offtopic and you haven't proposed a working alternative. Crypto nerds laugh even more at DANE (which just makes DNS providers CAs) and web of trust (sybill attacks). We could sit and design one together but getting the web to use it may take some time. Many have tried.
...but none of those are points from the article, which isn't about EV or DV.
Still challenging you to address any point in the article if you wish to.
However it's pretty clear that you didn't actually read the article, so you'll probably want to do that first.
1. Unicode Homograph attacks don't work in a business registration. Someone would have to be able to legally register a business name that fits your look-alike example. That is not possible in most places AFAIK.
So what you re actually pointing out is that domain names are vulnerable to these attacks, which is another reason why DV certificates can fall short.
2. Correct, different companies. This is as intended, but admittedly a weakness in the human-readability of EV certificates.
3. Not all roots can issue EV certificates.
4. It becomes much harder to remain anonymous if you do these things. You are right, it isn't impossible to register a company solely for malicious use. But it carries with it legal risk.
There are no Wildcard EV certificates. You are just describing Wildcards.
Crypto nerds do trust the HTTPS PKI that is why there are about a dozen industry-leading crypto people working at Chrome, Mozilla, etc on PKI crypto.
That's hardly controversial, I would have thought. If it's true, it's true whether or not the person telling you it sells EV certs.
Unwary PayPal users are regularly phished even though PayPal have EV certs because the average user doesn't know that authentic PayPal websites should always say "PayPal, Inc. [US]" in the address bar, and aren't concerned when the address bar says Secure instead.
I think the problem really is that we want users to be "safe" on the Internet without them having to learn anything, and the Internet just isn't there yet, and quite possibly never will be.
It's like trying to design a gun you can't shoot yourself in the foot with, because people won't put up with being taught gun-safety.
I do think we could benefit from new Internet users being made, probably by their browsers, to take a short training course in the basic aspects of what encryption really guarantees on the web, how recognise malicious websites, and the like.
Yeah it's kind of a game of whack-a-mole but at least get the low-hanging fruit.
> CAs need to do more and browser vendors should expect them to if they want to be included in the default bundle.
CAs _should not_ be expected to validate anything about a domain name other than who controls it (at least for DV certs). That's not their job, nor should it be.
First, it's not nearly as simple as blacklisting domains containing "PayPal" or "Gmail". What if, for example, someone wants to register a domain like "paypal-sucks.com" and use that to express their distaste for PayPal's business practices? Should they not be allowed to do that?
And what about wildcard certs? `*.some-site.com` matches `paypal.some-site.com` just as easily as it does `forum.some-site.com`. Do you expect CAs to police that somehow?
Maybe it would help to have something between the green "Secure" and the red "Danger! Stop!", e.g. an amber "warning" symbol implying that "You're connected to the site your browser is showing, but be sure it's the site you think it is." Sadly in reality I don't think that would go very far to solving the problem.
Warnings are only useful if they're shown rarely enough for users to take note of them as an unusual event when they do occur.