Hacker News new | ask | show | jobs
by fusiongyro 4985 days ago
Ideally, the information in the certificate is vetted by the certificate authority. So, if you have your company name, physical address, and contact info in there, the CA would have actually conducted some checks to make sure that information was correct and not fraudulent before certifying it. That vetting process costs time and money. Unfortunately, nobody can detect whether it has happened so now we have $5 certs that are essentially unvetted (uncertified certificates?) because people are only interested in the encryption component.