{"id":11591,"date":"2019-10-08T15:52:07","date_gmt":"2019-10-08T19:52:07","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=11591"},"modified":"2019-10-22T15:21:31","modified_gmt":"2019-10-22T19:21:31","slug":"online-identity-is-critical-lets-upgrade-extended-validation","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/online-identity-is-critical-lets-upgrade-extended-validation\/","title":{"rendered":"Online Identity Is Important: Let\u2019s Upgrade Extended Validation"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">It\u2019s time for the CA\/Browser Forum to focus on the other half of its\nmandate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s have a candid discussion about Extended Validation\nSSL. What\u2019s working. What\u2019s NOT. And what can be done to fix it so that all\nparties involved are satisfied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But first, let\u2019s zoom out and talk big picture. The vast\nmajority of website owners almost never think of SSL. They worry about it once\nevery year or so when it needs to be replaced, but it\u2019s not really a major\npoint of consideration. And even when it is, it\u2019s on more of a macro level when\nmanaging certificates at scale. Most site owners and organizations don\u2019t care\nabout industry politics or what\u2019s going on at some Forum in the same way that\nwe don\u2019t give a toss about what\u2019s going on at the American Dairy Association.\nAs long as there\u2019s milk on the shelves we just assume everything\u2019s fine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Right off the bat, we can admit that some of the arguments\nput forth against EV are valid to some extent. But we also believe that\nidentity is a major component of trust \u2013 a component that\u2019s even more critical\non the internet. That\u2019s why \u2013 in light of the complete lack of alternatives \u2013\nwe think fixing EV is a worthy discussion. We think this proposal is a\nreasonable way to address most of the major criticisms leveled against EV by\nits critics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, today we\u2019re going to talk about Extended Validation and\nwhat can be done to fix it. Then we\u2019ll propose several changes to hopefully\nkickstart a larger conversation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Is Extended Validation fulfilling its purpose?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start out with a quick overview of what specifically Extended\nValidation SSL is supposed to be accomplishing. This is the definition as it\nappears in the CA\/Browser Forum\u2019s EV Guidelines:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>The primary purposes of an EV Certificate are to:<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong><em>Identify the legal entity that\ncontrols a Web site:<\/em><\/strong><em> Provide a reasonable assurance to the user of\nan Internet browser that the Web site the user is accessing is controlled by a\nspecific legal entity identified in the EV Certificate by name, address of\nPlace of Business, Jurisdiction of Incorporation or Registration and\nRegistration Number or other disambiguating information; and<\/em><\/li><li><strong><em>Enable encrypted communications with a\nWeb site:<\/em><\/strong><em> Facilitate the exchange of encryption keys in order to\nenable the encrypted communication of information over the Internet between the\nuser of an Internet browser and a Web site.<\/em><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Ok, so, number two is really just a basic function of any\nSSL certificate. It doesn\u2019t matter if it\u2019s DV, OV or EV \u2013 they all facilitate\nencrypted connections. It\u2019s the first purpose that we\u2019re really debating when\nwe discuss Extended Validation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, let\u2019s break it down like this:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Does EV identify the legal entity behind the website? Yes. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Is the way it presents that information \u2013 as well as\nsometimes even the information itself \u2013 confusing? Yes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And that\u2019s really the biggest point of contention. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where some CAs are making a mistake \u2013 and please excuse our\ncandor here \u2013 is focusing on the secondary purposes as they advocate for EV. In\ncase you don\u2019t have your copy of the EV guidelines handy, here\u2019s what the\nsecondary purposes are defined as:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>2.1.2. Secondary Purposes<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>The secondary purposes of an EV Certificate are to help establish the\nlegitimacy of a business claiming to operate a Web site or distribute\nexecutable code, and to provide a vehicle that can be used to assist in\naddressing problems related to phishing, malware, and other forms of online\nidentity fraud. By providing more reliable third-party verified identity and\naddress information regarding the business, EV Certificates may help to:<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><em>Make it more difficult to mount phishing and\nother online identity fraud attacks using Certificates;<\/em><\/li><li><em>Assist companies that may be the target of\nphishing attacks or online identity fraud by providing them with a tool to\nbetter identify themselves to users; and<\/em><\/li><li><em>Assist law enforcement organizations in\ntheir investigations of phishing and other online identity fraud, including\nwhere appropriate, contacting, investigating, or taking legal action against\nthe Subject.<\/em><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The extent of EV\u2019s relationship with phishing is debatable,\nbut continuing to harp on this distracts from the better part of the argument \u2013\nthat a mechanism for asserting identity is critical for the internet\u2019s trust\necosystem. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That point is a lot harder to contend with, which brings us\nto\u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Criticisms of EV<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Generally, criticism of EV falls into one of three\ncategories:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>EV UI takes up real estate in the browser\u2019s address bar<\/li><li>People don\u2019t notice or don\u2019t know to look for EV UI <\/li><li>The validation portion of EV is broken and unreliable <\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">And again, each one of those criticisms has some validity. So,\nwe\u2019re going to take an objective look at each one before we lay out our\nproposal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">EV UI takes up real estate in the browser\u2019s address bar<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is a criticism first leveled\nby Google during deliberations at the CA\/B Forum. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>So the whole premise for why there should be *any* UI treatment is predicated on 2.1.2 (2), which clearly spells out that EV is a marketing tool, wrapped in the guise of a security tool. I do not feel you can offer a more charitable read of that section\u2026 Literally the entire value proposition of EV reduces to &#8220;CAs want to sell billboards in the browser&#8217;s security UI&#8221;. And the fundamental point is that such UI is security critical &#8211; it&#8217;s the line of death between trustworthy and untrustworthy content.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">What Google\u2019s rep just alluded to\nis a concept that is fairly sacrosanct to many in the browser community. <a href=\"https:\/\/textslashplain.com\/2017\/01\/14\/the-line-of-death\/\">Eric Lawrence\nelaborates on in a blog post<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>If a user trusts pixels above the line of death, the thinking goes, they\u2019ll be safe, but if they can be convinced to trust the pixels below the line, they\u2019re gonna die.<\/em><\/p><\/blockquote>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"292\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/line-of-death.png\" alt=\"Browser line of death\" class=\"wp-image-11593\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/line-of-death.png 720w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/line-of-death-300x122.png 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Everything above the red-dotted\nline is under the browser\u2019s control, everything below it is untrusted content.\nThat\u2019s not to say that it\u2019s necessarily malicious, just that the browser has no\ncontrol over it. If one of the primary functions for any browser is to keep its\nusers safe, ceding this much of the window only complicates that objective. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reason Google is so sensitive\nabout the space that an EV Visual Indicator occupies is because the browsers\nare already allowing some untrusted data to live above the line of death now,\ntoo. Lawrence illustrates this concept by creating zones:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"293\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/line-of-death-areas.png\" alt=\"Browser line of death\" class=\"wp-image-11594\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/line-of-death-areas.png 720w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/line-of-death-areas-300x122.png 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As Lawrence terms it, an attacker\nhas control over all the zones in red, leaving the browsers very little real\nestate to try and keep a user anchored and safe. If the browsers are going to\ncontinue renting space to CAs for a unique visual indicator, they want to make\nsure that there is sufficient value in that arrangement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s totally fair. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And we\u2019ve taken that into considering with what we\u2019re\nproposing. I think it\u2019s a bit cynical to say the CAs just want to sell\nbillboards, but that\u2019s pretty on-brand for the CA\/B Forum. Moving on\u2026<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">People don\u2019t notice or don\u2019t know to look for EV UI<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We wrote last week about the general lack of civility at the\nCA\/B Forum, as well as the fact that any research put forward by the CAs is judged\nto be tainted and unreliable. It\u2019s treated like junk science.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the rest of the Forum talks about whether the EV\nindicator is useful like it\u2019s been empirically proven.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s the thing: it hasn\u2019t.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Measuring whether or not people notice or use a trust\nindicator is incredibly difficult to quantify. You can\u2019t do it with a survey.&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The human brain can process images it sees for as little as\n13 milliseconds. As Nicholas Rule, a social psychologist that teaches at the\nUniversity of Toronto, writes in the Association for Psychological Science\u2019s\nObserver Magazine:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Before we can finish blinking our eyes, we\u2019ve already decided whether we want to hire, date, hate, or make friends with a person we\u2019re encountering for the first time. These first impressions color the way we interact with other people from that point forward. And all of this happens outside of our awareness, in the unconscious processes of the mind, research shows.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But that\u2019s first impressions of people. What about websites?\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The average internet user forms a trust decision within 50 milliseconds of arriving on a website. This according to a study performed by the Human-Oriented Technology Lab at Carleton College and published in the journal, <em>Behaviour &amp; Information Technology<\/em>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Our minds process millions of things on a daily basis on a sub-conscious level. This is called subliminal stimuli, it occurs beneath our threshold for conscious perception<\/em>. <\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">As Karin B. Jensen \u2013 who has a PHD\nin Neuroscience and teaches Psychiatry at Harvard \u2013 wrote in the International\nReview of Neurobiology just last year:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Subliminal means that a stimulus is presented below (sub) the threshold (limen) for conscious recognition, yet the stimulus can still affect behavior as it has been registered at a basic level of perception\u2026<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The point I\u2019m making is NOT that EV registers on a\nsubliminal level. It\u2019s that WE DON\u2019T KNOW.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I\u2019ve just cited science that was rigorously researched and\nreviewed by experts in their respective fields. By contrast, this is the\nmethodology employed by Google in the study that\u2019s widely cited as showing the\ncurrent security UI doesn\u2019t work:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>To motivate the need for new security indicators, we critique existing browser security indicators and survey 1,329 people about Google Chrome\u2019s indicators.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">So, to be clear, this is just a survey. Conducted by Google\npolling its own customers. And the phrasing \u201cto motivate the need for\u2026\u201d sort of\nfeels like Google already knew what it was hoping to find before it even\nstarted its survey. This would be considered tainted if it had come from the\nCAs. But petty grievances aside, this is far from scientific. It\u2019s tough to get\nexact figures on how many users Google Chrome has. But its mobile app alone has\nbeen downloaded more than 5 billion times. I mention this because 1,329 people\nis an infinitesimal sample size. And it\u2019s not measuring any of the cognitive\naspects of the decision.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Asking someone \u201cdid you notice this\u201d is unreliable. That\u2019s\nwhy witnesses are often discounted in criminal trials. There\u2019s a proven\ndisparity between what we process and what we remember. Even the godfather of\nuser research himself, Jakob Nielson (no relation to Leslie) once wrote:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>Too frequently, I hear about companies basing their designs on user input obtained through misguided methods. A typical example? Create a few alternative designs, show them to a group of users, and ask which one they prefer. Wrong. If the users have not actually tried to use the designs, they&#8217;ll base their comments on surface features. Such input often contrasts strongly with feedback based on real use.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Case in point, I drive 45 minutes to work each morning. On\nthe way I make use of all kinds of symbols and indicators to help me navigate,\nbut if you stopped me the moment I got out of the car and showed me a picture\nof a sign or symbol I drove past on the way, I couldn\u2019t tell you if I\nremembered it or not. And even if I could that would be unreliable because you\ndidn\u2019t actually see me use it that way. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I also couldn\u2019t tell you if I\u2019d noticed it had been removed.\nBut the corollary of that isn\u2019t that it\u2019s not useful. That\u2019s taking a leap.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most of the \u201cresearch\u201d on this topic is just anecdotal or\nits methodology only scrapes the surface of the human judgment process. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Again, the point I\u2019m making ISN\u2019T that the UI does or\ndoesn\u2019t work. It\u2019s that the research we have on both sides of the debate doesn\u2019t\nreally prove anything.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The validation portion of EV is broken and unreliable<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This point has some substance \u2013 but it\u2019s overstated. And\nnone of it is \u201cun-solveable\u201d as some so adamantly claim. Specifically, when it\ncomes to EV SSL, there are two major points of contention here. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The process can be exploited by attackers<\/li><li>The information provided can be confusing<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start with the first one, that the process can be\nexploited. Ian Carroll and James Burton both produced proofs of concepts that\nshowed how the EV system can be abused. Burton created a misleading\norganization name. Carroll created a naming collision. Technically both Burton\nand Carroll\u2019s exploit checks both boxes because the verified information is\nalso confusing. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the time, Burton opined:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>EV is on borrowed time and deprecating EV is the most logical viable solution right now and brings us one step forward in vanishing the old broken web security frameworks of the past. Now that both me and Ian have demonstrated the fundamental issues with EV and the way its displayed in the UI, it&#8217;s only time until the REAL phishing starts with EV.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Now, please show me the data if I\u2019m wrong, but that last\npart really hasn\u2019t happened, has it? There hasn\u2019t been an explosion of EV\nphishing. If you\u2019re going to argue EV doesn\u2019t stop phishing that\u2019s fine, but\nit\u2019s also not being used for phishing, either. The few cases where there\u2019s been\na rogue EV certificate were the result of site compromise. And there\u2019s a bit of\nconflation with the EV code signing certificates for sale on the dark web and\nEV SSL certificates. The latter is not all that prevalent. Again, show me the\ndata if I\u2019m wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While the validation portion of EV (and pretty much all SSL)\ncould do with some tweaking and improvements, you really do need to jump\nthrough a number of hoops to exploit it. (And many of those hoops require\ngovernment filings, which criminals typically try to avoid.) And the point where\nthings broke down with Carroll\u2019s POC was with the UK Companies House \u2013 not the\nCAs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other criticism is that sometimes the information\nprovided by EV can be confusing. Carroll\u2019s exploit was confusing because it\ncreated a name collision with the Stripe payment company. The SSL Store&#x2122; deals\nwith this, too. The SSL Store&#x2122; is a DBA, so our EV name plate says \u201cRapid Web\nServices, LLC.\u201d <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Our proposal: Mouse-over UI with LEIs included<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Our proposal really has three prongs, we just didn\u2019t feel\nlike putting the third in the header because education just isn\u2019t all that\nprovocative (really, none of this is). <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Mouse-over UI<\/li><li>Browser Home page educational messages<\/li><li>LEIs<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Like we did with the complaints, we\u2019ll go through each of\nthese suggestions one-by-one. Each is made to help address the major criticisms\nopposing EV. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Positive mouse-over EV UI<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start with the actual UI suggestion, which is to place\nthe EV UI in a mouse-over or hover-over box that displays the first time\nsomeone mouses over the address bar, and then again when someone hovers over it\nfor a couple of seconds. The indicator should also be differentiated with a\npositive symbol, too. Ideally something like Apple\u2019s Safari UI, which presents\nEV URLs in green. This would indicate more information is available. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This approach has a few benefits:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Doesn\u2019t take up browser real estate<\/li><li>Offers space to include more information<\/li><li>It\u2019s harder for users to miss<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Nobody on the internet is clamoring for less identity\ninformation to be available. Well, nobody reputable. As more and more people\nbecome aware of data security on account of the never-ending torrent of\nbreaches in the news daily, trust and identity are increasingly important. This\nwould provide a surefire way to display some information about the organization\nrunning the website in a way that\u2019s more noticeable to the user. If they don\u2019t\nlike it, let them turn it off with a flag or a setting, but most people will\nappreciate the expanded information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Right now, Mozilla offers a solid model for how this could\ngo:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"684\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mouseover-ev-ui-1024x684.png\" alt=\"Example mouseover UI for EV\" class=\"wp-image-11595\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mouseover-ev-ui-1024x684.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mouseover-ev-ui-300x200.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mouseover-ev-ui-768x513.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mouseover-ev-ui.png 1089w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, in its current iteration you have to click on\nthe padlock, then on the little arrow next to the connection field. And most\npeople really don\u2019t know where to look to find it this way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But if you start showing this data the first time someone mouses\nover the address bar they\u2019ll start looking for it. Aesthetically the browsers\ncan do it however they want, but if we at least partially standardize this\napproach some of the education takes care of itself, once people notice it\u2019s\nthere they\u2019ll find it useful. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That brings us to\u2026<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Educational messages on browser start pages<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When you open a web browser it takes you to a start page\nwith some favorites, maybe some news \u2013 but plenty of unused real estate.\nConsider that 95% of people never change their default settings and\nstatistically that means 19 of 20 internet users are seeing the same screen\nwhen they start up. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other thing these pages have in common, which we just\nalluded to \u2013 besides the fact almost every browser user sees them on a regular\nbasis \u2013 is that they have a lot of empty space. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And that space would be a perfect place to stick a small\nmessage advertising this new feature. Some browsers already display\ninformational messages like this:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"856\" height=\"90\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mozilla-message.png\" alt=\"Mozilla Firefox messages to browser users\" class=\"wp-image-11596\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mozilla-message.png 856w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mozilla-message-300x32.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/mozilla-message-768x81.png 768w\" sizes=\"auto, (max-width: 856px) 100vw, 856px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Because one of the misnomers that comes with the \u201cpeople\ndon\u2019t notice\/know to look for it\u201d argument is that the CAs have somehow failed\nto educate their customers about EV. But the CAs HAVE educated their customers.\nThat\u2019s why some organizations use EV in the first place. It shouldn\u2019t be\nincumbent upon the CAs to educate the browsers\u2019 customers. Should they do more?\nProbably. Is it solely their responsibility? No, the browsers need to be doing it,\ntoo. This is a partnership, SSL certificates are a support product. CAs don\u2019t\nhave a mainline to the browsers\u2019 customers, the browsers do. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And frankly, educating users shouldn\u2019t even be that hard.\nAgain, a quick notification on the Browser Home page should be sufficient. But\nwe need to standardize a UI first or no amount of education is going to have\nthe intended effect.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Add LEIs to certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s a ballot at the CA\/B Forum right now that\u2019s debating\nwhether this should happen. Here\u2019s some background: LEIs are Legal Entity\nIdentifiers, they were created in the aftermath of the financial crisis that\noccurred a decade ago. They are numerical codes recognized by 150 different\ncountries. The entire system is overseen by a Swiss non-profit called GLEIF.\nThe numbers are divvied out by Local Operation Units (LOUs).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Given the overlap between issuing digital certificates and\nissuing LEIs, a number of CAs are already operating as LOUs. Unfortunately,\nthere\u2019s one recalcitrant member of the forum that\u2019s gone so far as to suggest\nthey will unilaterally block this ballot and potentially distrust CAs that issue\ncertificates with LEIs included. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s hard to understand why. An LEI can help prevent collisions and confusion. As Stephan Wolf of GLEIF wrote in a recent CA\/B Forum email:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>The whole point of including an LEI is efficiency so organizations have a uniform, globally recognized and standards based unique 20 digit identifier that is machine readable, will never be reused,\u00a0and can be used to access other data using the same number.\u00a0<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Now, I can already hear the objections percolating, that,\nlike confusing organizational names, people won\u2019t know what to do with an LEI\nnumber. But there are several workarounds for that. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For one, the browser could just use the LEI code and\ngenerate the associated information. Granted that might require an additional\ncall, which may be anathema to browsers \u2013 but it\u2019s an option. You could also\nmake it easy to click on the LEI number and follow it to a database with the\ninformation. This would require the user to take an action, but some might find\nit useful. But more than anything, it could send up a red flag when an\neCommerce website or some other organization that transacts in valuable data\nDOESN\u2019T have an LEI. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Again, this debate is still in its infancy \u2013 but as Wolf wrote\nto Google:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>The LEI should be embedded in other eco systems for the greater good. I would like to state that LEI adds another layer of trust to EV certificates. Given your concerns about trust and evaluation, you should put yourself at the forefront of this project. The LEI has a lot of value for the Google user base among more.<\/em><\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Does anyone have a better idea?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The final point we\u2019re going to make is about the CA\/B Forum\nitself. Last month <a href=\"https:\/\/www.thesslstore.com\/blog\/ssl-certificates-one-year-max-validity-ballot-fails-at-the-ca-b-forum\/\">we\nmade a case for a return to civility<\/a>. Pretty much just asking everyone to\nstop acting like assholes. But one of the things we mentioned in that article\nis that the CA\/B Forum is really only fulfilling half of its mandate. From its\nown bylaws:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>The Certification Authority Browser Forum (CA\/Browser\nForum) is a voluntary gathering of leading Certificate Issuers and vendors of\nInternet browser software and other applications that use certificates\n(Certificate Consumers).<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Members of the CA\/Browser Forum have worked closely\ntogether in defining the guidelines and means of implementation for best\npractices as a way of providing a heightened security for Internet transactions\nand <strong>creating a more intuitive method of displaying secure sites to Internet\nusers.<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And here\u2019s the thing, nobody that\u2019s advocating for the end\nof EV has any kind of constructive suggestions for how to accomplish what it\nwas designed for. And what EV is trying to do is pretty universally regarded as\na good thing. It\u2019s just a matter of its efficacy. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If there was a competing approach that was being served as a\nreplacement that would be one thing. But eliminating it without any vision\ntowards a replacement does not make the internet safer or more secure. And\nthat\u2019s not in line with the Forum\u2019s stated goals. It seems like discarding EV\nwith no viable alternative just sets the whole internet backwards. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The internet can\u2019t afford to wait for us to figure something\nelse out. Again, identity has never been more critical. If you have another way\nto approach authentication and ID online, let\u2019s hear it. Otherwise, we should\nstart figuring out how to fix EV. Most of the CAs want to have that\nconversation. Whether or not it actually gets discussed \u2013 and earnestly \u2013 is up\nto the browsers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s time for the CA\/Browser Forum to focus on the other half of its mandate Let\u2019s have a candid discussion about Extended Validation SSL. What\u2019s working. What\u2019s NOT. And what&#8230;<\/p>\n","protected":false},"author":6,"featured_media":11613,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[11243,11244],"class_list":["post-11591","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-ev","tag-identity","post-with-tags"],"views":13729,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/encryption-and-identity.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11591","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=11591"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11591\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/11613"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=11591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=11591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=11591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}