Crapola: The Daily Rubbish

Tuesday, July 14, 2009

I Told You So, Again: EV SSL Is Stupid

PERMALINK || External link to topic of post

EV SSL Certificates Are No More Valuable
Than The Cheapest SSL Certificate

Not my quote, but matches my sentiments on the abomination known as EV SSL. Sure, this latest exploit is based on a specific use case (so far, that is), but that's really not the point.

EV SSL is nothing more than a cash cow and is an abomination that ultimately damages consumer confidence in "SSL" or the "padlock" by introducing the notion of "bad SSL" or the "not-so-good-browser-padlock".

If Certificate Issuers and Authorities are supposed to be the "entrusted" source for this technology, they simply must do their job and vet applicants. Its really that simple. Higher cost? Sure. Just don't introduce abominations that question your own reason for being, damages and confuses consumers.

Anyone can create a self-signed certificate, it really is that trivial. Certificate Authorities exist to do what the name implies. Be the Authority.

Labels: ,

0 Comments:

Post a Comment

Links to this post:

Create a Link

<< Home