Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As it stands, the majority of CA's do not verify any of this information, besides a very cursory email verification.

Exceptions would obviously include higher priced (OV/EV) certificates, which are no different cryptographically. Even the CA mentioned (GlobalSign) states this fairly clearly on their website.[1]

[1] https://www.globalsign.com/ssl-information-center/types-of-s...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: