{"id":12008,"date":"2020-01-29T16:23:45","date_gmt":"2020-01-29T21:23:45","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12008"},"modified":"2020-01-31T11:23:23","modified_gmt":"2020-01-31T16:23:23","slug":"digicert-leads-initiative-to-enhance-ev-ssl-certificates","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/digicert-leads-initiative-to-enhance-ev-ssl-certificates\/","title":{"rendered":"DigiCert Leads Initiative to Enhance EV SSL Certificates"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">In collaboration with several other certificate authorities, DigiCert has proposed 4 enhancements to the EV SSL validation processes<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/internet-dog-comic-1.png\" alt=\"Graphic: Comic stating &quot;On the internet, nobody knows you're a dog.&quot;\" class=\"wp-image-12011\" width=\"303\" height=\"337\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/internet-dog-comic-1.png 660w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/internet-dog-comic-1-269x300.png 269w\" sizes=\"auto, (max-width: 303px) 100vw, 303px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;On the Internet, nobody knows you&#8217;re a dog.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cartoonist Peter Steiner penned those words in a cartoon strip all the way back in 1993. The cartoon was funny and made a lot of people laugh, but it was highlighting a serious issue that was just developing back then\u2014how easy it was to trick people via the anonymity of the internet. Unfortunately, Peter nailed it! Today, that problem is even bigger than anyone \u2013 even Peter \u2013 could have imagined\u2014<a href=\"https:\/\/www.thesslstore.com\/blog\/20-phishing-statistics-to-keep-you-from-getting-hooked-in-2019\/\">1 in 25 branded emails is actually a phishing email<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, why is online identity so important? How will DigiCert\u2019s\nproposal help consumers?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Online Identity Is So Important<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The internet is flooded with unknown actors, and a lot of\ntimes they\u2019re up to nefarious activities\u2014phishing, bullying, catfishing, scamming,\npreying on children, swatting, and more. That\u2019s why most internet users tend to\nbe suspicious of interactions with people, websites, and companies they don\u2019t\nknow\u2014typically, we want to know the real-world identity of the individuals and\ncompanies we interact with online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What would you think if you went to your local shopping\ncenter and saw a shop with no business name, like this?<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"682\" height=\"467\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/unknown-business.png\" alt=\"Graphic: An illustration of an unknown business\" class=\"wp-image-12012\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/unknown-business.png 682w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/unknown-business-300x205.png 300w\" sizes=\"auto, (max-width: 682px) 100vw, 682px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019d be intrigued \u2014 but you probably wouldn\u2019t trust that company. You\u2019d certainly have some questions! Customers don\u2019t trust anonymity \u2014 they want to know who they\u2019re doing business with.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same thing is true online \u2014 customers want to know who they\u2019re buying from. At your local mall, it\u2019s pretty easy to tell who you\u2019re buying from \u2014 there\u2019s a physical store with signage and staff right in front of you. Online, though, identity can be\u2026 slippery. As Steiner pointed out, you can be a dog, a scammer, or a predator\u2026 and nobody will know until it\u2019s too late.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In an environment saturated with anonymous trouble-makers, EV SSL is a great tool consumers can use to confidently see who runs a website, helping them decide whether to trust the website owner or not. That\u2019s why we strongly support making EV SSL as strong and usable as possible \u2014 people want\/need what it can provide. And that\u2019s why we\u2019re excited to see DigiCert leading the charge to update and enhance EV SSL.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DigiCert\u2019s 4-Pronged Proposal to Enhance EV SSL<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DigiCert is proposing four specific ways to update and enhance the CA\/B Forum standards for EV SSL certificates. These enhancements will make EV SSL stronger and satisfy some \u201cweaknesses\u201d pointed out by security researchers. Let\u2019s go through each of them, and see how they\u2019ll help improve online identity for all:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Enforce Validation Level via CAA Records<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A CAA record is a DNS entry that lets website managers restrict which CAs may issue certificates for their domain. It\u2019s a great tool for fighting shadow IT certificates \u2014 ensuring that an organization\u2019s certificates are centrally managed and authorized. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But currently CAA records can only specify certificate\nauthorities. DigiCert is proposing expanding CAA records so domain admins can control\nor restrict the validation level of certificates that can be issued for their\ndomain. For example, a website admin could restrict their domain to only issue EV\nSSL certificates from a certain CA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why This Is Beneficial:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s look at a hypothetical scenario. Let\u2019s say example.com hires a freelance web designer to update their blog with a fresh, new design for 2020. That designer isn\u2019t authorized to issue SSL certificates for the domain. But let\u2019s say the website designer installs a WordPress file editor plugin, so they can complete domain control validation and get an SSL certificate issued. Example.com now has an SSL certificate issued by an unauthorized party \u2014 they don\u2019t control the certificate or the private key, which is a significant security issue. What happens when the certificate expires?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If example.com had implemented a CAA record that restricted\nthe domain to EV certificates from DigiCert CA only, the web designer wouldn\u2019t\nhave been able to get that certificate issued because any attempt to get a\ncertificate type not identified in the CAA record would fail.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Include LEI Data in SSL Certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019ve got a feeling of d\u00e9j\u00e0 vu right now, it might be because <a href=\"https:\/\/www.thesslstore.com\/blog\/online-identity-is-critical-lets-upgrade-extended-validation\/\">we mentioned this idea back in October 2019<\/a>. TL;DR:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>LEIs are Legal Entity Identifiers, they were created in the aftermath of the financial crisis that occurred a decade ago. They are numerical codes recognized by 150 different countries. The entire system is overseen by a Swiss non-profit called GLEIF. An LEI can help prevent collisions and confusion. Now, I can already hear the objections percolating, that, like confusing organizational names, people won\u2019t know what to do with an LEI number. But there are several workarounds for that. For one, the browser could just use the LEI code and generate the associated information. Granted that might require an additional call, which may be anathema to browsers \u2013 but it\u2019s an option. You could also make it easy to click on the LEI number and follow it to a database with the information. This would require the user to take an action, but some might find it useful. But more than anything, it could send up a red flag when an eCommerce website or some other organization that transacts in valuable data DOESN\u2019T have an LEI.&#8221;<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why This Is Beneficial:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adding LEIs to EV SSL certificates offers two key benefits:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>adds additional information about the\norganization, and<\/li><li>provides consumers a direct way to research and\nverify company details for myriad reasons.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you look up a company in the LEI database, you\u2019ll get a\nreport with a lot of details about the organization. Starting with basic info:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"673\" height=\"417\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/microsoft-corporation-lei.png\" alt=\"A screenshot of Microsoft corporation's LEI information\" class=\"wp-image-12013\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/microsoft-corporation-lei.png 673w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/microsoft-corporation-lei-300x186.png 300w\" sizes=\"auto, (max-width: 673px) 100vw, 673px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">And even including information about subsidiaries and parent\ncompanies:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"676\" height=\"382\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/children-lei.png\" alt=\"A screenshot of Microsoft Corporation's LEI children information \" class=\"wp-image-12014\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/children-lei.png 676w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/children-lei-300x170.png 300w\" sizes=\"auto, (max-width: 676px) 100vw, 676px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">In the end, this info is ripe for being used as another data\npoint to solve any corporate identity assurance use case. Like EV SSL, the\ninfrastructure is already in place, why not use it (or at least consider it) for\nresolving such an apparent problem? &nbsp;&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Standardize Data Sources for EV Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Under the current EV guidelines, each certificate authority decides what data sources they will use for validation of organization details in EV SSL certificates. (Keeping in mind that they\u2019re validating organizations across hundreds of countries, there can be a lot of variation in the quality of data sources being used from country to county.) DigiCert is proposing that the CA\/B forum specify a standardized list of acceptable data sources to use in the EV validation process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why This Is Beneficial:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using standardized data sources will offer several benefits:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>improve the consistency and speed of EV validation,<\/li><li>close some potential gaps bad actors could use,\nand<\/li><li>this could be used as a basis to deal with\nnaming collisions (which has been one of the criticisms against EV\u2014for de\nminimis reasons if you ask me.)<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4. Include Trademark Verification During EV Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Since EV SSL certificates are all about showing customers\nthe verified identity of the organizations they\u2019re interacting with, trademarks\nare a logical add-on. As DigiCert\u2019s Dean Coclin explains:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Trademarks are well known, understood, unique and can be validated. Consumers recognize them and so if a browser wanted to include the trademark in their UI, they could do so with confidence that it had been properly validated. If they don\u2019t, that\u2019s fine, but it would be in the cert for any relying party to examine.\u201d<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why This Is Beneficial:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trademarks are another way for consumers to be sure they\u2019re interacting with the company they think they are. For example, Windex is a trademark owned by the SC Johnson company. But many consumers probably don\u2019t know the Windex brand is actually owned by SC Johnson. The current EV guidelines state that it can only say SC Johnson. However, if their EV SSL certificate displayed the Windex trademark, that might help a consumer be more confident that they\u2019re on the official and intended website.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<h2 class=\"wp-block-heading\">The Other Part Of The Equation: Browsers\u2019 Need An Effective UI To Display\nWebsite Identity Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ultimately, for EV SSL certificates to reach their full\npotential in helping users, the browsers need to research, identify and\nintroduce a more effective interface for displaying identity information to\nusers. (Incidentally, the browser\u2019s identity interface wouldn\u2019t have to be\nlimited to data from EV\u2014it could contain data from other verified sources to\nprovide consumers all the data they need to make an informed decision.) <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since Chrome and Firefox removed the old \u201cgreen address bar\u201d\ndue to concerns that it wasn\u2019t effective, the onus is on the browsers to\ndevelop a new UI that helps users understand who is running the websites\nthey\u2019re interacting with. In my opinion, removing EV without replacing it with\na viable alternative did the world a huge disservice. EV may not have helped 100%\nof internet users, but it certainly helped more than 0%. It wasn\u2019t perfect, but\nit was all the internet had. It\u2019s like saying, since automobile accidents still\nhappen at intersections, get rid of all traffic lights until we think of\nsomething better. For some reason, logic just seemed to go out the window on\nthis one. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It doesn\u2019t seem like too big of an ask for the browser\ncommunity to seriously come together and help create a universal display that\nwill help consumers with the identity of websites that they interact with. I\nthink if browsers put their users\u2019 interests first, the answer will come very\neasily.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Social Media Sites Have Already Created a UI for Online Identity, Let\u2019s\nLearn From Them!<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">I took 15 minutes with my team and came up with a half-baked\nidea that seems to make quick sense. One of the big things that the EV\nnaysayers harped on was that the \u201cgreen address bar\u201d needed education to\nunderstand what it actually meant. They believed that it should require no\ntraining or education and that it should just be immediately understood. Well,\nin minute three of our discussion, we realized that all of the social media channels\nover the past decade have already educated the world on this exact problem. The\nsocial media eco-system recognized issues with identity and addressed it\nhead-on years ago by introducing the verified account status symbol. A verified\naccount status is reserved for high-profile accounts of companies, brands or\nindividuals that are especially vulnerable to impersonation. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"676\" height=\"340\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/taylor-swift-verified-status.png\" alt=\"Graphic: Screenshot of Taylor Swift's verified account on Twitter.\" class=\"wp-image-12015\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/taylor-swift-verified-status.png 676w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/taylor-swift-verified-status-300x151.png 300w\" sizes=\"auto, (max-width: 676px) 100vw, 676px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">For obvious reasons, fake accounts that are used to\nimpersonate a popular user on a social media platform could easily cause\nirreparable brand damage to both the real account holder and the platform\u2019s\nbusiness model. That\u2019s specifically why the verified account status and symbol\nexist. Well, since the social media channels have already done the educating\nand have fully conditioned users at scale to look for verified account symbols\nwhen consuming content, why not adopt that developed behavior to work in\nbrowser environments? It can quickly be used to address online identity on a\nwider scale than just social media. Seems like the logical next step. Does it somehow\ngo against browser business models?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Below is what we came up with over a cup of coffee. For DV\nSSL, since the lock doesn\u2019t mean what it used to, simply hide it. Then let\u2019s\nintroduce two, or maybe just one, verified website symbol. I\u2019d bet that if you\ndid a study, users would immediately understand what this means. Without\neducation. With conviction. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"677\" height=\"302\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/secured-vs-not-secured-examples.png\" alt=\"Graphic: Examples of how not secure and secure websites could look\" class=\"wp-image-12016\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/secured-vs-not-secured-examples.png 677w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/secured-vs-not-secured-examples-300x134.png 300w\" sizes=\"auto, (max-width: 677px) 100vw, 677px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Mousing over the verified icon could display a tooltip\nshowing more specifics on what the icon means.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"671\" height=\"150\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/example-of-verified-status.png\" alt=\"Graphic: Example of how a verified website status could look in a browser\" class=\"wp-image-12017\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/example-of-verified-status.png 671w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/example-of-verified-status-300x67.png 300w\" sizes=\"auto, (max-width: 671px) 100vw, 671px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you click on it, something like this could display. It\u2019s\nvery similar to what used to be displayed, but with a few tweaks. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"674\" height=\"577\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/verified-identity-secure-website-example.png\" alt=\"Graphic: An example of how a verified website can assert identity with an SSL\/TLS certificate\" class=\"wp-image-12018\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/verified-identity-secure-website-example.png 674w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/verified-identity-secure-website-example-300x257.png 300w\" sizes=\"auto, (max-width: 674px) 100vw, 674px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Just to reiterate, this idea would be after the EV guidelines have been enhanced. I\u2019m sure there are more things worth consideration, but this took us 15 minutes in an informal meeting setting. I wonder what a group of browser security experts and security researchers could come up with if they tried to solve online identity head on\u2026 for the sake of Internet users. At the least, it\u2019s worthy of a real discussion where all parties come together to really solve a larger issue for the greater good of society. Not just go through the motions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the Internet, nobody knows you\u2019re a legit website.\nDigiCert is trying to do something about it. Browsers, you\u2019re up.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In collaboration with several other certificate authorities, DigiCert has proposed 4 enhancements to the EV SSL validation processes &#8220;On the Internet, nobody knows you&#8217;re a dog.&#8221; Cartoonist Peter Steiner penned&#8230;<\/p>\n","protected":false},"author":28,"featured_media":12023,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130,16,10200],"tags":[3628,11243,366,3556,11538],"class_list":["post-12008","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","category-hashing-out-cyber-security","category-monthly-digest","tag-digicert","tag-ev","tag-ev-ssl","tag-extended-validation","tag-lei","post-with-tags"],"views":12986,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/01\/digicert-ev-blog-image2.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12008"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12008\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12023"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}