top | item 42313665

(no title)

drew-y | 1 year ago

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

discuss

order

marionauta|1 year ago

Some HTTP certificates do exactly that, and web browsers used to show the company/identity the certificate was issued to in the URL bar. Now you have to go to the certificates detail, very clear on Firefox, behind a few clicks on Chrome. Here's an example from a bank in Spain: https://www.bbva.es

varenc|1 year ago

HTTPS certificates should do exactly this.

drew-y|1 year ago

They should. And sort of already do. Though, I wonder how difficult it is to register with some certificate issuers under a fraudulent name.

chrismorgan|1 year ago

That was EV certificates. They were finally removed from browsers completely around five years ago because they didn’t actually work. At all. The problems were largely social. Plenty has been written about it, you can find it by searching.

Joker_vD|1 year ago

Well, the original HTTPS certificates too were supposed to work like that; I remember reading a security article criticizing the EV proposal by quoting the old (circa 1998?) policy statements of different CA's and showing that they're pretty much identical to the EV requirements.