|
|
|
|
|
by ocdtrekkie
631 days ago
|
|
While I enjoy Google relaunching EV certs under another name to avoid it was just wrong about claiming they were useless and a bad idea... the cost is the point. One of the biggest things people just don't get is that anything cheap and automatic is easily exploitable at scale, and things expensive and manual are much harder to exploit, and generally speaking not worth the cost. The reason people got the idea the lock icon in the browser meant a site was legitimate is because malicious sites rarely ever paid for a certificate. Now that certificates are free, of course, all phishing sites use Let's Encrypt. EV and VMC certs are not generally speaking exploited simply because it isn't worth the cost to do so. |
|