Cynicism is healthy. The TLS industry has historically been quite shady. Symantec was selling 'Step up' encryption certs for Internet Explorer 5.5 pre 5.5 SP1 in 2015 as a value add. Comodo tried to trademark 'Let's Encypt' for some reason that still isn't clear.
I'm quite happy for people to ignore the article I wrote, read Section 7.2 of Google's research, and verify for themselves the claim made in the title.
Then consider whether most people understand that 'Secure' means 'Secure from eavesdropping' as the quoted Google engineer suggests.
- You're handling sensitive data and want to prove
there's a real company behind the site, rather than just
someone who registered a domain.
1.) Unicode homoglyph attacks means "Goοgle Inc" looks just like "Google Inc". All browsers mitigate IDN attacks, but the way unicode strings are handled means the browser vendors have to be lucky forever, while an attacker just has to be lucky once.2.) "Widget Inc" is a different legal entity from "Widgets LLC". Is some clerk in Delaware going to care that an attacker is registering a name vaguely similar to the name of your California corp? Probably not.
3.) Chrome uses the OS cert store. As of 2016, Windows trusts 356 root certificates. Any root can sign a cert for any domain name. How much do the owners of "TUBITAK Kamu SM SSL Kok Sertifikasi Surum 1" care about your security?
4.) It costs, what, a hundred bucks to register a corp online? Easy spend if you're spearfishing a high value target. "Shell-company-as-a-service" has been a value provider of law firms for centuries.
- You have other people pretending to be you and want to
distinguish your site from theirs.
Wildcard EV certs let anyone in the world register "yourcorpname.customer-service.io", or "yourcorpname-help.com" Large corporations train users to do this, hilariously. In order to log into office 365, you visit... login.microsoftonline.com. - You're a crypto nerd and the idea of connecting to
random public keys makes you boak.
Crypto nerds don't trust the HTTPS PKI at all.1. Unicode Homograph attacks don't work in a business registration. Someone would have to be able to legally register a business name that fits your look-alike example. That is not possible in most places AFAIK.
So what you re actually pointing out is that domain names are vulnerable to these attacks, which is another reason why DV certificates can fall short.
2. Correct, different companies. This is as intended, but admittedly a weakness in the human-readability of EV certificates.
3. Not all roots can issue EV certificates.
4. It becomes much harder to remain anonymous if you do these things. You are right, it isn't impossible to register a company solely for malicious use. But it carries with it legal risk.
There are no Wildcard EV certificates. You are just describing Wildcards.
Crypto nerds do trust the HTTPS PKI that is why there are about a dozen industry-leading crypto people working at Chrome, Mozilla, etc on PKI crypto.
- a legitimate point (2)
- Three points that indicate you don't have experience of EV (1 - you would have to prove you're legally 'Google Inc' with a homoglyph to a CA, which would be difficult, 3 as vtlynch mentioned, Timbuktu CA is unlikely to issue EV certs and if it does so would be required to be audited on how well it meets the EV for CAs requirements and 4, wildcards are expressly forbidden for EV).
- some which are against PKI, which is great but even more offtopic and you haven't proposed a working alternative. Crypto nerds laugh even more at DANE (which just makes DNS providers CAs) and web of trust (sybill attacks). We could sit and design one together but getting the web to use it may take some time. Many have tried.
...but none of those are points from the article, which isn't about EV or DV.
Still challenging you to address any point in the article if you wish to.
However it's pretty clear that you didn't actually read the article, so you'll probably want to do that first.