Re: Different Colors for different Certificate Authorities
Ali Khalfan <[email protected]> Fri, 23 Sep 2016 11:32:34 +0300
| Newsgroups | gmane.comp.mozilla.wishlist |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============8846243733977262771== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="f1PFX56tVXh65UVsKVPiJ3X4cPQe6Nhqd" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --f1PFX56tVXh65UVsKVPiJ3X4cPQe6Nhqd From: Ali Khalfan <[email protected]> To: [email protected] Message-ID: <[email protected]> Subject: Re: Different Colors for different Certificate Authorities References: <[email protected]> In-Reply-To: <[email protected]> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable anybody besides spammers can give me any feedback on this? -------- Original Message -------- Subject: Different Colors for different Certificate Authorities From: Ali Khalfan <[email protected]> To: [email protected] Date: Wed Sep 14 2016 08:49:24 GMT+0300 (AST) > Regular users are told to lock for the SSL lock to make sure the site i= s > secure. In the old days, it was a lot harder to get an SSL certificate= > without some sort of rigorous verification (e.g. registration document,= > whois repository, proof of actual owner of the entity owning the domain= ). > > It is a lot easier to get a valid SSL certificate today. Some > certificate authorities, such as Truecrypt, provide certificates simply= > if proof is provided that a domain is owned. Because Truecrypt mainly > cares about encryption. Needless to say, a miscreant setting up a > phishing website does own a domain. So, encryption is provided but not= > authenticity. A regular user will look at the lock, which is green, an= d > think the site is secure (while it is not).=20 > > I would think different colors should be on the bar based on the > certificate authority. If the certificate is signed by an authority > known to perform rigorous verification it should be different from a > certificate signed by an authority verifies by a simple e-mail > verification.=20 > > > Thanks, > Ali > --f1PFX56tVXh65UVsKVPiJ3X4cPQe6Nhqd Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJX5OirAAoJEF9xp9NDNF0kw7IQAJmXqNuqitfydn0dFkzgmQM3 U1Q5LSwez6RK7i+bBbFnUzW8O7O2ncZDJnOWzPcamnYwmjcIdAi8zeJL1/P3Qvek +YckQfQiMh+0NZWrvfw+UveFo2m0mli5VTqXWPGxRyPtQn9v61wsMmYrqFh8CKlk C+JT6OlQUJxbBocnMUOiQzafwSj9LGV6fs1goQLPuyYd/ahQzyBxzjkz2UxF1T2Y mrX56FRd7Tie2CU9Q0gyHk6J5uSpaZ/L1wZkJ5+/vgAlmwziLwM6Yg7+RQZPPXt1 mLAy7dheNZ0JKY5DCJLzck0GZf7O7LgVGCbpsE0Ab8A3KFylb5pAdgnSq4eUc3kM BYwUpl5RpPePsO3N823tKdouSAuOYyMbOebCWJxBiZkVHY9N8/mSLgHEF3QH9cl0 XTx1FdnEcxKWCJE1hzBwV/fzCkTpFL9xpf+sCs9O+GiIKQxDU4gkhSB2+ZsW61vs CUEUoCzT5UqNsJNtTnqZhzfU3TLGQyf2k5hULzUGee40jANnHnbLyGFM4Q/V0ChB eRxbNLOispWs5rfzWRfWdBG/F7C10TfrdbjLCRxyRTtR1wSfVgeUc0U0XIUQ6UdR rn41InYrNoED8ryvQRlOA+NKrk3AnYuyO0+isrSEu5dM0g7gxkkSEce7BqyRhXgH Im9e09+/fLaLURM07ctA =Q/Ba -----END PGP SIGNATURE----- --f1PFX56tVXh65UVsKVPiJ3X4cPQe6Nhqd-- --===============8846243733977262771== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ wishlist mailing list [email protected] https://lists.mozilla.org/listinfo/wishlist --===============8846243733977262771==--