I wonder how they're planning to handle EV certificates. They don't seem to be mentioned anywhere in this post. I seem to recall at least one person at Google advocating for removing EV indicators entirely.
I wonder how they're planning to handle EV certificates. They don't seem to be mentioned anywhere in this post. I seem to recall at least one person at Google advocating for removing EV indicators entirely.
Argument 1: this person was able to get an EV cert for "Stripe, Inc. [US]", an entity they registered in Kentucky, no relation to the Stripe, Inc. of California whose website is stripe.com. They were not able to get a certificate for stripe.com. (The CA revoked it, and then later apologized for revoking it because there was no reason by their policy to do so.) https://stripe.ian.sh/
Argument 2: the actual website for MasterCard's SecureCode is https://www.mycardsecure.com/ , whose EV cert is "Arcot Systems LLC [US]". The fact that it has a meaningless domain name is in no way fixed by it having a meaningless (but technically accurate, Arcot is the contractor for SecureCode) EV cert. How do you know you're actually supposed to type your personal information there?
Argument 3: the web's security model is based on origins (domain names), not on EV certs. If Stripe switches tomorrow to stripeiscool.com and a domain squatter gets stripe.com, my browser will still send cookies to stripe.com, even though it no longer has an EV cert, and it certainly won't send cookies to stripeiscool.com, even if it has an EV cert with the same organization. Even if EV were a good idea in the abstract, it lacks a plan to make it work with the web as actually deployed.
There are obviously issues with EV as it's currently implemented, but I believe the solution to that is to fix those issues, not to eliminate the indicator entirely.
Attack 1 makes me worry about whether this is solvable at all. There's a lot of "First Bank and Trust"s out there, and they'd all need an EV certificate for the same string, so avoiding the attack seems genuinely hard. Like social media (or curated app stores), the only way it can really work is if the "verified" marker creates first-class and second-class entities: the entities approved by the powerful as reasonable to do business with, and the entities that aren't. Someone makes a decision about which First Banks and Trusts are "real" and which ones aren't, and you can't appeal it.
A site you're looking at with an EV cert you're happy with might have an image that's supposed to say "Sorry, we're closed for maintenance" with the site's logo. But bad guys, who have a DV cert have substituted "Welcome, please use our new login system". They've also replaced the cool live map and fancy animated carousel below that with their "new" login form. So the site has the EV visuals, but bad guys who broke only DV can subvert it almost totally.
Do you know the thinking behind getting rid of the EV indicator? Is EV considered useless?
Edit: Just as I posted this, someone else answered my question: https://news.ycombinator.com/item?id=17093737