{"id":5501,"date":"2017-12-06T12:49:08","date_gmt":"2017-12-06T17:49:08","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=5501"},"modified":"2017-12-07T00:07:59","modified_gmt":"2017-12-07T05:07:59","slug":"eliminating-secure-dv-ssl-indicator","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/eliminating-secure-dv-ssl-indicator\/","title":{"rendered":"Baptists &#038; Bootleggers: Consensus on Eliminating the Secure DV SSL Indicator"},"content":{"rendered":"<h2>Sometimes the internet creates strange bedfellows.<\/h2>\n<p>In 1982, an Economist at Clemson University named Bruce Yandle <a href=\"https:\/\/www.mercatus.org\/video\/bootleggers-and-baptists-conversation-bruce-yandle\" rel=\u201dnofollow\u201d>concocted an economic theory<\/a> that he articulated using the old tale of the Baptists and the Bootleggers.<\/p>\n<p>As the anecdote goes, both the Baptists and the Bootleggers agreed that the bars and liquor stores should be closed on Sunday. The Baptists were teetotalers and wanted them closed to get a break from the demon drink. The bootleggers wanted them closed so they could sell their wares.<\/p>\n<p>The outcome, says Yandle, is \u201cdurable regulation that will stick around as long as the Baptists and the Bootleggers have a common objective.\u201d<\/p>\n<p>Keep that theory in mind because it\u2019s never been more applicable to the SSL industry than in the current debate over Browser UI and how it displays for DV SSL certificates.<span id=\"newline\"><\/span><\/p>\n<p>That occurred to me this morning, following this interaction:<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">I want to abolish security indicators, you want to sell them. That we &#8220;agree&#8221; on abolishing DV indicators is more a coincidence than any kind of agreement on the issue.<\/p>\n<p>\u2014 hanno (@hanno) <a href=\"https:\/\/twitter.com\/hanno\/status\/938423685463072768?ref_src=twsrc%5Etfw\" rel=\u201dnofollow\u201d>December 6, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\" rel=\u201dnofollow\u201d><\/script><\/p>\n<p>Granted, I don\u2019t think the Certificate Authorities and resellers that are \u201ctrying to sell\u201d SSL certificates are as nefarious as bootleggers. But certainly, some in the industry do seem to feel that way.<\/p>\n<p>Regardless, I think by this point we can all agree the Secure DV SSL indicator needs to go. It\u2019s creating more problems than its solving. And while discussions of a uniform UI and EV treatment remain, there seems to be a consensus on DV.<\/p>\n<p>There are two main factors behind why the DV UI is failing. The first is the rapid proliferation of DV SSL certificates. The second is Google\u2019s change to its UI itself.<\/p>\n<p>Starting at the beginning of the year, Google began marking websites with DV or OV SSL certificates &#8220;Secure,&#8221; and it is slowly beginning to mark HTTP sites &#8220;Not Secure.&#8221; Though Google <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-security-indicators\/\">tested for different UIs<\/a>, the one it ultimately decided on was the &#8220;Secure&#8221;\/&#8221;Not Secure&#8221; binary. As pretty much everyone throughout the industry knows, users don&#8217;t have much of an idea what the old visual indicators meant and this was an attempt to simplify things for them.<\/p>\n<p>Unfortunately, it went the other way. People mistook &#8220;Secure&#8221; for safe and acted accordingly.<\/p>\n<p>Phishing is now at an all time high. According to one threat report, <a href=\"https:\/\/www.nttsecurity.com\/docs\/librariesprovider3\/default-document-library\/ntt-security-GTIC-2017-q3-threat-intelligence-report.pdf\" rel=\u201dnofollow\u201d>phishing is up 74% in Q3 2017<\/a>. There are <a href=\"https:\/\/www.thesslstore.com\/blog\/1-4-million-new-phishing-websites-created-every-month\/\">1.4 million new phishing sites created each month<\/a>, on average. And according to a <a href=\"https:\/\/info.phishlabs.com\/blog\/quarter-phishing-attacks-hosted-https-domains\" rel=\u201dnofollow\u201d>PhishLab report issued yesterday<\/a>, a quarter of all phishing is now done via HTTPS.<\/p>\n<figure id=\"attachment_5503\" aria-describedby=\"caption-attachment-5503\" style=\"width: 690px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-5503\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/phishing-sites-hosted-on-https-1.png\" alt=\"Secure DV SSL indicator\" width=\"690\" height=\"537\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/phishing-sites-hosted-on-https-1.png 640w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/phishing-sites-hosted-on-https-1-300x233.png 300w\" sizes=\"auto, (max-width: 690px) 100vw, 690px\" \/><figcaption id=\"caption-attachment-5503\" class=\"wp-caption-text\">Courtesy of PhishLabs<\/figcaption><\/figure>\n<p>It\u2019s being done using DV certs, too. Here\u2019s a look at the last 30 days, 99.5% of the HTTPS phishing sites sampled were DV.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-5504 size-large\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/PhishingSiteChart-690x1024.jpg\" alt=\"Secure DV SSL Indicator\" width=\"690\" height=\"1024\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/PhishingSiteChart-690x1024.jpg 690w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/PhishingSiteChart-202x300.jpg 202w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/PhishingSiteChart-768x1140.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/PhishingSiteChart.jpg 1585w\" sizes=\"auto, (max-width: 690px) 100vw, 690px\" \/><\/p>\n<p>And that makes a lot of sense. It&#8217;s easy to get a DV SSL certificate nowadays. There are free CAs, DV certs come bundled as part of hosting packages now and there are even programs with commercial CAs where you can get a DV SSL certificate without paying a cent.<\/p>\n<p>We think this is great. The problem is: if Domain Validated SSL is the new default, why is it getting such a strong indicator?<\/p>\n<p>Now, from all of thus data, there\u2019s no way you could prove a causal link between Google&#8217;s UI and this decided uptick in HTTPS phishing. But there is DEFINITELY a correlation. Keep in mind, the chart below is from last Spring, that line would be at the top of the graph now.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4419\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/07\/HTTPS-Phishing-Websites.png\" alt=\"Netcraft Graph Showing an increase of HTTPS Phishing Sites\" width=\"690\" height=\"412\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/07\/HTTPS-Phishing-Websites.png 975w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/07\/HTTPS-Phishing-Websites-300x179.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/07\/HTTPS-Phishing-Websites-768x458.png 768w\" sizes=\"auto, (max-width: 690px) 100vw, 690px\" \/><\/p>\n<p>My understanding of Google\u2019s ultimate plan was that it wants to eliminate the Secure DV SSL indicator once enough of the internet has migrated to HTTPS. And that probably seemed like the ideal way to do it at the time.<\/p>\n<p>Things have changed. The current UI makes phishing websites with SSL certificates \u2013 which is now about one in four sites \u2013 more effective.<\/p>\n<p>The Secure DV SSL indicator needs to go.<\/p>\n<p>When even the Baptists and the Bootleggers can agree on that\u2014you know it\u2019s time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sometimes the internet creates strange bedfellows. In 1982, an Economist at Clemson University named Bruce Yandle concocted an economic theory that he articulated using the old tale of the Baptists&#8230;<\/p>\n","protected":false},"author":6,"featured_media":5505,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[131,170,166],"class_list":["post-5501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-google","tag-https","tag-phishing","post-with-tags"],"views":10847,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/12\/iStock-183283589.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=5501"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5501\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/5505"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=5501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=5501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=5501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}