Chrome, Firefox Ditch EV SSL Padlock System
Chrome and Firefox will stop indicating when websites have received an "extra level of verification" to prove they are in fact genuine. The move is largely due to the fact that most users aren't aware of the Extended Validation SSL (EV SSL) system.
The Extended Validation SSL (secure socket layer) security certificates go beyond the standard SSL certification scheme, which browsers use to show that data being sent to and from a website is in fact encrypted and secure. This means that communication is encrypted, and that no one can eavesdrop or steal data mid-stream. In other words, the site uses a secure connection.
In addition to SSL, Extended Validation certificates prove that the certificate is in fact owned by the organization they claim to be. Though, technically speaking: if a website with Extended Verification was hijacked (by hackers, for example), "proof of ownership" in the form of an SSL certification wouldn't have any merit, anyway.
That aside, getting an Extended Validation SSL certificate costs businesses extra as it involves human checks, rather than purely automated verification. The check makes sure the organization really exists: for example, that a business is registered and has a valid physical location such as an office.
Organization Name Appears in Address Bar
If a website has Extended Validation SSL, the name of the organization operating it appears in the address bar between the padlock symbol (showing a secure site) and the website address.
The system was introduced in 2007. If you'd never heard of it - you're not alone.
Both Google and Mozilla both say their browsers will stop showing the organization name in the address bar, and instead any Extended Validation SSL certificate details will only appear when users click on the padlock symbol to get more information about the page.
According to Google, research shows the system is so little known that it isn't effective. There's also no evidence that the presence or absence of the Extended Validation organization name makes any difference to whether users correctly gauge whether a site is trustworthy. (Source: googlesource.com)
Major Sites Shun System
It's been a bit of a chicken-and-egg situation. One of the reasons many users don't know about the system is because many leading websites - including ten of the largest sites online - simply don't use the system. And, the reason many sites don't use the system is because users don't know about it. (Source: zdnet.com)
It's also part of a change in policy by Google to move away from "positive security indicators", which it finds ineffective, and instead emphasize negative indicators such as highlighting when a website is "not secure".
Drawing attention to sites that don't have Extended Validation would be both confusing (because it would happen on so many legitimate sites) and arguably unfair - because the web tech community doesn't consider Extended Validation SSL certificates to be a must-have.
What's Your Opinion?
Have you ever noticed the name of an organization before the website address? Did you know it indicated a site with Extended Validation? Are the browser makers right to stop indicating it?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Seen it
I've seen it a few times, I like the idea they are trying to do. I can't see why the indication would make any difference to the browser itself.
Agreed it's a terrible idea
Agreed it's a terrible idea to imply that any site is more secure just because it's extra validated. Just makes good phishing attempts even easier to pull off when you fake that and certs mean nothing when there are so many stolen CA keys floating around and CAs operated by, if not malicious then at least not impartial, actors like state intelligence agencies