The Dangers of HTTPS and Extended Validation Certificates

Extended Validation (EV) certificates are an advanced type of digital certificate that websites use to enable HTTPS. Their purpose is to help fight phishing sites by allowing the official websites of legitimate companies to show the name of the company in the URL bar. In practice, though, EV certificates can be dangerous when dealing with phishing sites.

Introduction to HTTPS and EV Certificates

Before getting into the specifics of how Extended Verification (EV) certificates can be a threat, let’s briefly discuss what HTTPS and EV certificates are.

What Is HTTPS?

Pretty much everyone has heard of HTTPS. They know that when they’re using the Internet, it’s important to make sure that the address bar has that “green padlock.” As long as a website has the lock, it’s reputable and perfectly safe.

Not really. HTTPS doesn’t actually provide any guarantee that a website is safe or even who it claims to be. The only thing that HTTPS promises is that the owner of the website has a trusted digital certificate for that website and that your connection to that website is encrypted. This makes it an improvement over ordinary HTTP, which does not provide authentication or encryption; but while HTTPS is necessary to browse the Internet securely, seeing the green padlock doesn’t mean that you’re safe.

To get a green padlock, all someone has to do is get a digital certificate for that domain. Services like Let’s Encrypt make this quick and easy, allowing anyone to set up a site protected by HTTPS. The only obligation for these services is to make certain that the person requesting the certificate actually has control over the website.

This means that phishing websites can have certificates too. In fact, over a quarter of phishing sites now use HTTPS. The burden is on the (Read more...)

*** This is a Security Bloggers Network syndicated blog from InfoSec Resources authored by Howard Poston. Read the original post at: http://feedproxy.google.com/~r/infosecResources/~3/mwHUZIzvSOE/

Recent Posts

NewDay Scores with TigerGraph Cloud to Fight Financial Fraud

Leading UK Credit Card Consumer Finance Company Uses Advanced Graph Analytics to Intercept Fraudulent Credit Card Applications, Boost Anti-Fraud Efforts…

1 hour ago

VMRay Closes $25 Million Series B

Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…

3 hours ago

The Hacker Mind Podcast: Hacking OpenWRT

For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…

3 hours ago

Goodbye to Flash – if you’re still running it, uninstall Flash Player now

It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…

4 hours ago

Being a Defender

1. Be a student of (information security, network security, cyber security). Always strive to know what the latest tactics, trends,…

4 hours ago