Hacker News new | ask | show | jobs
by AnthonyMouse 3932 days ago
If it says "bankofamericaa.com" your alarm bells should start ringing. Even assuming the attacker can't get a certificate for the right country, how is the user expected to notice (and understand) the wrong country code if they can't notice the wrong domain name?
1 comments

I'd argue it's at least simpler to notice since it's more readable - it has spaces between words.
Notice that by this point the claimed benefit of the EV cert has lost all connection to the validation process and is now solely an artifact of the impermissibility of spaces in host names.