Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

The only real validation that actually works is certificate pinning built into the browser itself - and even that only guarantees that Google.com is signed by Google - not that goooooooogle.orgbiz.com.au is properly marked as a scam.


The term validation is overloaded so I’m avoiding it.

EV is/was proof of identity. And proof of identity needs a scalable solution for the web. Certificate pinning won’t scale unless the browser knows all possible certificates in advance.

Knowing whether something is a scam is a separate topic from verification. Think of other verification systems - people may be known, but bad. Admittedly twitter muddied the water here terribly by removing verification badges from people that twitter considers to have broken their terms of service.


The problem is that proof of identity doesn't really give you much when you dig into it - either it's after the fact (which is what happens with EV, even if someone DID scam using one, AND it was traced back to what was likely a shell company).

It's literally why banks were massive stone buildings - proving that they had the resources to build a solid thing that wasn't going to move or change was a part of establishing their identity as a something that can be trusted.

So the equivalent for EV would have been to make them cost ... say ... $185,000 to register and $25k a year - wait, that's a TLD and would be a much more powerful form of identity and ... it's not used at all. https://google.google redirects to ... google.com




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: