EV Certificate Effectiveness

This cluster debates the value and effectiveness of Extended Validation (EV) SSL/TLS certificates compared to Domain Validation (DV) ones like Let's Encrypt, questioning their ability to provide real security and user trust amid issues with Certificate Authorities.

➡️ Stable 0.5x Security
4,088
Comments
20
Years Active
5
Top Authors
#5067
Topic ID

Activity Over Time

2007
4
2008
30
2009
17
2010
47
2011
92
2012
81
2013
137
2014
277
2015
431
2016
383
2017
474
2018
362
2019
315
2020
238
2021
144
2022
291
2023
268
2024
195
2025
293
2026
9

Keywords

StartCom e.g DigiCert DV GoDaddy PKI UI EMV DNS IMO ev certificates certificate let encrypt encrypt certs cas cert ca let

Sample Comments

immibis May 28, 2024 View on HN

Because Let's Encrypt is the CA that hands out certificates without actually verifying identity.

cjbprime Aug 26, 2023 View on HN

Why do you think it's a false sense of security? Are you familiar with Certificate Transparency? And Let's Encrypt?

steve_taylor Nov 3, 2022 View on HN

Isn't this something that Extended Validation certificates were designed to address?

sublinear Jan 31, 2023 View on HN

In theory isn't this what EV certs are for? I know users don't really notice though.

nerdponx Nov 28, 2018 View on HN

I thought this was the point of EV certs.

captn3m0 Oct 30, 2020 View on HN

Sadly research has proven otherwise:1. Users do not understand the difference between an EV and a DV cert. We spent a decade training users that the padlock is all you need.2. Company registration norms are not standardised across the world, and you can easily get a certificate for Microsoft Corp, see https://news.ycombinator.com/item?id=15904513 for eg.

vidarh Feb 10, 2016 View on HN

There's nothing stopping the spammers from getting certs.

cm2187 Jul 31, 2019 View on HN

EV certs required that. DV certs never provided that sort of security.

theamk Nov 2, 2019 View on HN

This sounds just like EV certificates, and they have not been shown to work very well.(There have been many articles explaining why, here is one: https://www.troyhunt.com/extended-validation-certificates-ar... )

tptacek Mar 28, 2011 View on HN

Why do you trust DNS registrars more than you trust CAs?