Re: Proposal: Marking HTTP As Non-Secure
Kevin Chadwick <[email protected]> Tue, 2 Feb 2016 15:59:03 +0000
| Newsgroups | gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> > this connection is encrypted but do you > > trust the domain "?.co" > > BTW: If this domain was ?.ltd.uk it could potentially be extended to, > this domain is controlled by company no. 12345678 who have been > established for 4 years and owned this domain for two years. The > current directors have been in place for 4 years. > > I personally think that would be far more useful than an EV cert which > I pay no attention to whatsoever and I am a security professional. Sorry, last addition. I realise nominets process may not be so vetted as EV but on top of their simple checks, the domain must be aligned with the company name which if a user trusts said company name, which they **MUST** check anyway then said company will likely defend that domain name space also. -- KISSIS - Keep It Simple So It's Securable -- You received this message because you are subscribed to the Google Groups "Security-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]