Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

not for proving identity - how do you prove that ebay is ebay or that bank site really is Barclays and not some scammer


Not with SSL certs anyway.

At least not as long as your browser trusts hundreds of CA's, including shady ones such as Comodo[1] who will issue fake certs to any name (Google, Skype, etc.).

[1] https://www.schneier.com/blog/archives/2011/03/comodo_group_...


The fact that Comodo is occasionally scammed (a headline-generating event) does not prove that they add no level of identity authentication.


With an email hostmaster/webmaster@example.com and/or a DNS record. EV certs require more, but DV certs have their identities verified automatically in seconds.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: