Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

EV certs don't look as cool as they used to. The green they use is to close to black. I know Edge got rid of the green bar as well but the green they use stands out.


I feel like I'm missing something here, as both you and the article heavily imply that Chrome displayed EV certs prior to 52. In my experience, Chrome hasn't displayed EVs; here's an EV cert site for me under Chrome 51: https://i.imgur.com/azKdzPd.png — this is the same presentation it gives DV certificates.

(The same site in Firefox: https://i.imgur.com/yrtypBZ.png )


Chrome requires Certificate Transparency for the EV indicator to be displayed - see https://news.netcraft.com/archives/2015/08/24/thousands-shor...


Here's a screenshot of the EV UI prior to this change: https://ftt-uploads.s3.amazonaws.com/browser-ssl-ui-comparis...

It's possible that some sort of corporate MitM proxy is replacing the certificate in your case, or it's CT-related, as mentioned in a sibling comment.


I'd see a MitM in the cert chain if I manually inspect it, wouldn't I? (It'd be signed by the corporate MitM CA cert, right?)

Interesting that it shows up in your screenshot though; BoA on both Chrome 51 (on OS X) and Chrome 51 on Linux doesn't display the EV for BoA, or GitHub.

(I doubt the MitM one, since the Linux machine is my home one. The OS X one is my corp laptop, so corp MitM'ing is believable there.)

or is the screenshot incredibly outdated, since it says Chrome 8, and CT came later?


> I'd see a MitM in the cert chain if I manually inspect it, wouldn't I? (It'd be signed by the corporate MitM CA cert, right?)

Yep, it should show up in the cert chain.

> Interesting that it shows up in your screenshot though; BoA on both Chrome 51 (on OS X) and Chrome 51 on Linux doesn't display the EV for BoA, or GitHub.

I'd guess for some reason Chrome doesn't think it has received a qualified SCT for the certificate and is refusing EV treatment. Not sure which SCT delivery methods Chrome supports, and why they might be failing here.

> or is the screenshot incredibly outdated, since it says Chrome 8, and CT came later?

It's definitely old, but I don't believe it's related. FWIW I'm getting the EV UI on OS X with Chrome 54 when I visit https://www.bankofamerica.com/.


Author here. It's a more accurate reflection of what EV offers: it's about matching identities to certificates, not 'selling green bars' the big CAs have been doing for years.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: