Because the authorities trust anyone who pays them 20 bucks. THEN, the users trust any site where the address bar turns yellow. Do you see the break in the chain here?
Because the authorities trust anyone who pays them 20 bucks. THEN, the users trust any site where the address bar turns yellow. Do you see the break in the chain here?
Then you switched to say that you can't really trust Authorities. Maybe so, but the current setup seems better to me than the alternatives.
Second, my argument has always been that the browser should not harass the user of a site that has not taken part in this PHONY identification procedure.
Heck, even google adsense has seen through this scam and not bothered to pay the fee.
Edit: To clarify, most users equivocate signed SSL certificate == trustable site. That is WRONG. Verisign does not vigorously establish the non-evilness of your site.
Example: http://blog.washingtonpost.com/securityfix/2006/02/the_new_face_of_phishing_1.html