Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure I follow. How are EV certificates weak? They use the same cyphers and just have extra validation on the owner/domain.


It appears to be more of a UI issue where the legal entity name is shown along side or sometimes in place of the URL which can be misleading.

To compound problems legal entity names are not required to be unique across states or countries so an EV certificate for a popular company name can be obtained in another geography and presented to the user on an attacker controlled domain.

https://www.bleepingcomputer.com/news/security/extended-vali...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: