Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I remember many moons ago, like the Netscape era, when companies that paid for EV certs got special icons and a green address and all sorts of browser indications of trustworthiness.

I just tried my (large, international) bank website in the latest Safari, and I can't even figure out how to view the cert. There's an assumption that every site will have some cert, but no special treatment for EV certs at all.



In Chrome you can click on the icon next to the address and then on security, it will show the name of the company the cert is issued to. Quite hidden though.

But yeah, Safari is always something i have trouble finding the cert, they are really hiding it.


Well it can be bypassed by setting up a new company with the same name. Someone had done that against stripe I remember.


EV certs show the company name and the country, for disambiguation, on the assumption that you cannot have two companies of the same name in the same country. However, this is not true in the USA, where names are unique only within each state.

That's how someone got an EV cert for Stripe (USA).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: