What database/records do you think the cops check when you call in a complaint?
You can call in a complaint about a bogus website to them too, and it’s even easier to figure this out? (From being familiar with those databases)
The issue is that unlike someone with a physical presence in a specific place which makes someone vulnerable to being physically arrested, the internet makes it easy to do something that would otherwise result in that consequence from a place where that consequence is impossible.
And no amount of traditional records and ‘call the cops’ type processes are going to address that. And no amount of extra visible information somewhere in a place that will be overwhelming and ignored is going to fix it either.
Cops are about physical restraint (generally), aka ‘arrest’, which is the only proven ‘lowest common denominator’ way anyone seems to have figured out to ACTUALLY stop someone from doing something. You take them physically, put them in a cell where they can’t access anything but the things you hope they can’t abuse, and hold them until another resolution is figured out or you have to release them anyway.
To avoid problems like a random cop in rural Arkansas from going to Washington and arresting the president, the area different police are able to do this in is restricted, various rules and laws, etc. further restrict when, where, and how they can do it, etc.
Fundamentally that means most cops are helpless in this scenario unless said bogus website scammer is dumb enough to scam people in his same town/city/state/whatever.
And unless everyone takes a ‘scam unless proven innocent’ approach which pretty fundamentally breaks the internet’s usefulness, CA signing and the like doesn’t really solve any of that problem, no matter how accurate the information is.
On the one hand, we're supposed to trust no one on the web, on the other hand the web is only useful if we're effectively trusting everyone (except the most obvious scammers).
Right now we have no solution, we’re relying on ‘mostly works’ real world stuff to stop the biggest scams, and lots of small scammers are running around scamming lots of people and not being punished for it.
If someone does a big enough scam on a big enough target (like a crypto ransom on a major oil pipeline), they’ll get the attention of someone who can ‘bend the rules’ enough to make their life hell and get you anyway, no matter where you are. But that doesn’t stop them from ruining a ton of people who aren’t that noticeable. Because those people aren’t noticeable, it’s also a lot of value that can be extracted that way, which makes the problem worse.
Most people currently consider it working well enough to be better than the alternatives based on overall numbers.
however as the scam economy develops, which it has been doing, something is going to break.
it’s not going to go in the direction of random police officer in Vietnam, Nigeria, or Russia arresting his buddy (no matter how solid the evidence looks) because someone in the US wants it to happen.
Think what happened with email and spam in the late 90’s - up until that point, spam filtering was a niche thing only nerds did. Then it got to the point email was useless without it, and thankfully for email, spam filtering worked and the providers provided it.
Phones, phone providers haven’t been interested in, so except for some business cases almost no one uses phones directly any more (it’s texts or everything to voicemail first or whatever).
So no idea how this is going to go - curated marketplaces for anyone online? Federal/EU Gov’t certs to do business online? ‘Great firewalls’ to keep the scammers out/limit traffic to where it can be policed? Consumers bailing on online purchases except for specific already known and ‘trusted’ names?
this is not a solved problem - that's the whole point. there is no general way to verify trust on the web. We can verify trust in certain connections or transactions, but it's not possible to trust "the web". and until the problem is solved, anybody trying to sell a way to do that is selling snake oil.
Ok, but then why actively block attempts to tackle this problem?
Yes, there are edge cases in which EV certs can be confusing, but in general they give a guarantee that you're dealing with a registered company from a country with generally respected business standards. That's a lot better than the current state where the site might as well be served from a raspberry pi in some teenager's basement.
If the company's name is not sufficient to identify them, put an address in there, too, or registration number or whatever. I don't get what's so hard about this.
And as for "people are ignoring them", I'm sorry, but this is largely the browser vendors' fault. For a long time, people were ignoring cert errors as well. Browser vendors reacted with a massive UI revamp up to intentional dark patterns to change behaviour here - and it worked.
Meanwhile, with EV certs, UX went into the exact opposite direction: Browsers were increasingly de-emphasizing the EV data, to the point that people are actively discouraged from looking it up. No wonder then that no one checks EV information.
"in general, except for the edge cases" is the opposite of a guarantee. they create a situation where users assume a level of trust that can't be actually guaranteed, which is exactly what fraudsters exploit.
browsers aren't actively blocking attempts to tackle this problem. browsers are blocking schemes which falsely claim to tackle the problem.
You can call in a complaint about a bogus website to them too, and it’s even easier to figure this out? (From being familiar with those databases)
The issue is that unlike someone with a physical presence in a specific place which makes someone vulnerable to being physically arrested, the internet makes it easy to do something that would otherwise result in that consequence from a place where that consequence is impossible.
And no amount of traditional records and ‘call the cops’ type processes are going to address that. And no amount of extra visible information somewhere in a place that will be overwhelming and ignored is going to fix it either.
Cops are about physical restraint (generally), aka ‘arrest’, which is the only proven ‘lowest common denominator’ way anyone seems to have figured out to ACTUALLY stop someone from doing something. You take them physically, put them in a cell where they can’t access anything but the things you hope they can’t abuse, and hold them until another resolution is figured out or you have to release them anyway.
To avoid problems like a random cop in rural Arkansas from going to Washington and arresting the president, the area different police are able to do this in is restricted, various rules and laws, etc. further restrict when, where, and how they can do it, etc.
Fundamentally that means most cops are helpless in this scenario unless said bogus website scammer is dumb enough to scam people in his same town/city/state/whatever.
And unless everyone takes a ‘scam unless proven innocent’ approach which pretty fundamentally breaks the internet’s usefulness, CA signing and the like doesn’t really solve any of that problem, no matter how accurate the information is.