Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

doesn't the gray padlock currently mean the site isn't 100% secure? Meaning the page itself is but an asset isn't?


I always disable mixed content so I honestly wouldn't know browsers indicate mixed content. I was under the impression that yellow was used. Apologies for the confusion.

My point in my previous comment was that browsers should consider exposing the distinction between EV and DV certs to the user in a way that doesn't break their mental model of how browsers indicate the security of websites. How this is implemented is probably better handled by others more knowledgeable in UI design than I.


Safari (at least on the Mac) shows EV certificates with a green padlock and the organization name, which I think makes it nicely clear. PayPal shows up as "<green padlock> PayPal, Inc. www.paypal.com" whereas a scam site will just show "<gray padlock> paypal.com.scammers-r-us.com."

Teaching people to look for this might be hard, though.


Organisation names are not, to people's surprise, globally unique. I don't have a Mac but a common "solution" there is to add a country flag, so an Australian firm named Top Burgers gets a different flag icon from an Irish firm by the same name.

But wait, is the burger place you like the Irish one or the Australian one? The faux German decor and the American accent of their spokespeople on TV give no hint. Turns out - neither, the Top Burgers you love are legally named Upper Deck Barbecue and Burger Company, Inc., and so their EV would need that mouthful on it.

So yeah, EV isn't worthless, but it's probably not going to fix anything much you'd actually care about. If I ran a business with PayPal's money I'd get an EV cert because the price is a rounding error. But for 99.99% that's money they could spend on security or customer service improvements that'd see an actual return.


It'll be way harder to get an EV certificate for "Paypal Inc." than to get a DV certificate for paypal.com.scammers-r-us.com. Getting two legitimate companies mixed up is a problem, but far less of one than getting a legitimate company mixed up with a scammer.


I believe that's a padlock with a strike through. Possibly grey or yellow, I'm not sure.


This is how it looks in latest chrome: http://imgur.com/a/3R48U




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: