As long as you, the user, trust that the browser itself hasn't been modified (for example if you downloaded it yourself), then it's a nice reassurance when using a browser in a not totally trusted environment.
As long as you, the user, trust that the browser itself hasn't been modified (for example if you downloaded it yourself), then it's a nice reassurance when using a browser in a not totally trusted environment.
HTTPS is a nice reassurance, sure, but an EV cert isn't.
It used to be. All his EV certs were revoked.
And people who would follow the correct behaviour...are probably capable of doing so without the EV anyway.
No, I don't believe it is. The point debunked over and over again by Troy in this and other articles of his is the supposed anti-phishing aspect of EV certs: that because the browser shows the company name separate from the url, the user can know that they're really at e.g. Amazon and not amaz0n.com.
I'm referring to a very specific situation that is much more rarely mentioned: when you are using a computer with a managed cert store (usually a company computer behind a firewall) and you want to know if the site you are visiting is getting "legitimately" (per company policy) SSL-sniffed by a network appliance. This is completely different from phishing attacks or whether you think you are at the real Amazon. All you need to do is go to a single site that you know has EV and see if it shows up as EV in the browser. Sure, they could selectively sniff, but in practice I believe most companies that do this have an all or nothing approach.