Re: Proposal: Marking HTTP As Non-Secure

Kevin Chadwick <[email protected]> Tue, 2 Feb 2016 15:59:03 +0000
Newsgroups gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <[email protected]>
> > this connection is encrypted but do you
> > trust the domain "?.co"  
> 
> BTW: If this domain was ?.ltd.uk it could potentially be extended to,
> this domain is controlled by company no. 12345678 who have been
> established for 4 years and owned this domain for two years. The
> current directors have been in place for 4 years.
> 
> I personally think that would be far more useful than an EV cert which
> I pay no attention to whatsoever and I am a security professional.

Sorry, last addition.

I realise nominets process may not be so vetted as EV but on top of
their simple checks, the domain must be aligned with the company name
which if a user trusts said company name, which they **MUST** check
anyway then said company will likely defend that domain name space also.

-- 

KISSIS - Keep It Simple So It's Securable

-- 
You received this message because you are subscribed to the Google Groups "Security-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]