Woah! Which CA issued your EV?
cc. @JonKaltwasser
-
-
-
Any CA would have issued that certificate, it is a legitimate business name and he was able to demonstrate control. Business names are not unique.
-
Ah, right. Good point!
What about comparing new EV requests to a DB of already issued certificates (e.g. by the name/location of the legal entity)? 
-
More difficult than that, Stripe, Inc could be a pavement striping company. should they be able to get a certificate with their business name in it? Maybe it is not pishing now but like most phishing sites its hacked and becomes one later?
-
Uhhh... Indeed, that’s hard.
But at least a CA would know about such collisions and could (in theory) classify/monitor them as high risk.
Preventing (non-financial) businesses from obtaining an EV cert isn’t a good solution IMHO. 
-
Phishing just isn't a pre-issuance check, and revocation checking even if deployed in workable fashion is a bad anti-phishing tool. Things like SafeBrowsing and Smart Screen are designed for this scenario, EV just isnt.
-
Yesss!
@Google Safe Browsing FTW.
End of conversation
New conversation -
-
-
on my Safari it shows the URL in addition to the name... do you not get the same thing? what version are you running? I am on 11.0.2pic.twitter.com/aJgb4RjlRl
-
That's a Safari setting (advanced) you have to turn on to display full website addresses in the "smart search field," i.e. URL bar.pic.twitter.com/xhBmkUvLtn
-
yeah, i do have that checked. Don't remember checking it, but i must have at some point.
End of conversation
New conversation -
-
-
Well done, great write-up, and excellent description of the issues.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Cert is revoked now? :/
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Coming soon: EMEV certificates (Even More Extended Validation)
https://twitter.com/iangcarroll/status/940281927789146112 …
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
While not built in it is possible to view a cert in mobile Safari with Inspect app https://itunes.apple.com/us/app/inspect-view-tls-certificate/id1074957486?mt=8 …
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@G_Princen Il est de plus en plus difficile de se protéger.Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Yes, Next.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Safari users: Best enable “Show full website address” to at least mitigate this somewhatpic.twitter.com/6hNQb5BBpZ
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
oh no
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.