Hacker News new | ask | show | jobs
by Qwertie 2880 days ago
I heard the cost of EV certs is pretty high so it's much less likely a scammer will buy an EV cert vs just a similar domain and a regular cert.
1 comments

Took this guy $177 to register a Delaware corporation called Stripe Inc and get Comodo to issue him an EV certificate that looks exactly like the real payment gateway. After Comodo revoked his cert, GoDaddy gave him one.

https://stripe.ian.sh/

EV certificates tell you that a site is owned by a company with a particular name, not that it is the company you actually want. There's a reason browser vendors are de-emphasising EV: it isn't very useful.