I fundamentally think this is not a solvable problem using certs. Short of calling up the company directly and asking no amount of signaling in the browser will help.
Also why do I care about an EV cert as a user? does it tell me anything actually useful? Things I do care about as a user:
* Is my connection encrypted? (Browsers tell me this just fine)
* Is the site known to be malicious? (Browsers tell me this just fine)
* Have I been MiTM'd (Browsers protect against this just fine)
Things I don't care about as a user:
* Is this site actually owned by a specific Corporation?
Literally have never cared. Not once. Knowing this has never made me more secure or given me more confidence because fundamentally knowing who someone on the internet is does not tell me how trustworthy they are without way more context.
For physical banks, every piece of stationary from my bank states their domain name so once I have a DV verified showing I'm actually connected to that domain I can trust it.
For online banks, I only got to them online by which automatically means I have their correct domain name.
The question of how I get the online bank's domain name to begin with does not really come in to this conversation, can be an ad, a friend etc.
Most people don’t visit URLs by typing them into their browser. Links, messaging apps, email, native apps etc. account for more than manually typed links do.
The EV UI was sunset in all browsers because as it turns out, ensuring that your address bar says 'wellsfargo.com' and that you didn't get MITM'd is plenty good enough due to the other protections.
The only real validation that actually works is certificate pinning built into the browser itself - and even that only guarantees that Google.com is signed by Google - not that goooooooogle.orgbiz.com.au is properly marked as a scam.
The term validation is overloaded so I’m avoiding it.
EV is/was proof of identity. And proof of identity needs a scalable solution for the web. Certificate pinning won’t scale unless the browser knows all possible certificates in advance.
Knowing whether something is a scam is a separate topic from verification. Think of other verification systems - people may be known, but bad. Admittedly twitter muddied the water here terribly by removing verification badges from people that twitter considers to have broken their terms of service.
The problem is that proof of identity doesn't really give you much when you dig into it - either it's after the fact (which is what happens with EV, even if someone DID scam using one, AND it was traced back to what was likely a shell company).
It's literally why banks were massive stone buildings - proving that they had the resources to build a solid thing that wasn't going to move or change was a part of establishing their identity as a something that can be trusted.
So the equivalent for EV would have been to make them cost ... say ... $185,000 to register and $25k a year - wait, that's a TLD and would be a much more powerful form of identity and ... it's not used at all. https://google.google redirects to ... google.com
If I had my time again I would have sold part of CertSimple to Google with the aim of integrating with Google My Business so Google would make money from verification.
I feel this would prompt browsers to care about robust identity - both in terms of better verification and better display.
Web browsers told me they'd try better verification markers for years. They never did. So we don't know, except to say:
a. the 'green bar' verification marker isn't very effective.
b. the 'blue tick' logo as used for UIs like https://twitter.com/troyhunt hasn't been tried so browser makers have no data here.
It's a moot point: the realpolitik is browsers don't care about identity as it's not in their financial interest to do so.
Disclaimer: I spent 5 years of my life trying to verify the web.