Hacker News new | ask | show | jobs
by viraptor 314 days ago
Why would that be disregarding safety? There's no extra text you can put on the website that would prove anything else (apart from messages signed by a known key, but honestly nobody would check those). Certificates don't provide any identity validation in practice.
1 comments

Certificates have fields for location, company or name of person.
They mean very little. Even the fully reviewed software signing cert I got with id validation was a total hack job (company didn't know how to read my ID, asked to change some field and they did).
So you're suggesting we should bring back extended validation? Currently they don't mean anything.