Extended Validation "spoofing" by colliding entity names

General discussion and chat (archived)

franzk

Re: Extended Validation "spoofing" by colliding entity names

Unread post by franzk » 2017-12-15, 07:40

viewtopic.php?f=26&t=15583
I'm not sure if it is needed?
Both the HTTPS cert entity and the uri is presented in the address bar.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35602
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Extended Validation "spoofing" by colliding entity names

Unread post by Moonchild » 2017-12-15, 08:53

If your browser doesn't provide essential information to verify the identity of the site you visit, then this is a problem. I don't know which browser it is displayed in that article but having just the EV org name displayed is BAD, for this exact reason. You must always show the address or at least the domain to prevent spoofing.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35602
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Extended Validation "spoofing" by colliding entity names

Unread post by Moonchild » 2017-12-15, 09:02

dark_moon wrote:I wonder if we can fix this
it would be nice if you first verify next time you're scouring the net for security articles that things even apply to us before you insinuate that this is something that needs fixing in Pale Moon. It'll save me a lot of time having to check into these articles and evaluating applicability every time. Thanks in advance.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Locked