Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I actually found EV useful especially when logging in financial websites. Of course most people can't make the difference between http and https but I thought this issue will only be fixed by time.


That's actually how I found out my Lenovo was doing MITM a few days before the whole Superfish debacle exploded on the net. I went on Bitbucket (I think) and noticed something seemed different, I realised it wasn't showing an EV certificate: I dug deeper and saw that the issuer was suspect.

I feel that EV certificates do have their use for high-worth targets (banks and so one). Getting one is not trivial and definitely not scalable. Maybe they are a bit overpriced, maybe the certificate industry is kind of sketchy, but that's other debates.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: