Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?
I first noticed that it wasn't intercepting my connection to my bank, and then after some experimentation, that turned out to be the pattern. Sounds stupid, but there you go, somebody uses EV as a signal for something.
As it turns out it appears to intercept everything except connections to major high street banks.
These days I can't be bothered to circumvent. If I want to do any sort of sensitive browsing at work (e.g. online banking) I just tether my laptop to my phone.
With the EV certs, you can be assured that it actually belongs to the company it claims to belong. If I see "PayPal, Inc. (US)" in the address bar, I'm sure I'm accessing the correct server. However, I didn't really know that business names are not unique between different US states, but I assume this is not the case for other countries.
The issue with EV certs is how they are presented in the browser, since they are indistinguishable to the ordinary certs, at least to the majority of the users.
Uniqueness of business entity names is something you should never ever assume or rely on.
EV certs are currently the cash cow of certificate authorities. If you'd take away EV certs it would become apparent that there's no valid business model for CAs any more.
So the whole CA industry kinda depends on keeping the illusion that EV is a valid concept.
I really wouldn't care for a web shop etc.