Hacker News new | ask | show | jobs
by realityking 3933 days ago
Part of the label is also the country, if it says "Bank of America [AZ]" your alarms bells should start ringing.
1 comments

If it says "bankofamericaa.com" your alarm bells should start ringing. Even assuming the attacker can't get a certificate for the right country, how is the user expected to notice (and understand) the wrong country code if they can't notice the wrong domain name?
I'd argue it's at least simpler to notice since it's more readable - it has spaces between words.
Notice that by this point the claimed benefit of the EV cert has lost all connection to the validation process and is now solely an artifact of the impermissibility of spaces in host names.