Welcome, Guest. Please login or register.
November 15, 2009, 06:11:46 AM

Login with username, password and session length

334792 Posts
37021 Topics
83934 Members

Latest Member: sola1

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Melih's Corner - CEO Talk/Discussions/Blog
| | |-+  Yellow padlock is losing its trusted status :(
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: Yellow padlock is losing its trusted status :(  (Read 6638 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 8216



WWW
« on: June 25, 2009, 11:48:47 PM »

SSL losing its trust

This is a new video i have prepared to educate people about SSL and the issues with it.

Melih
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #1 on: June 26, 2009, 12:01:34 AM »

Indeed it is, mostly to us users that know how easy it is to get one. To normal every day users it’s a False Sense of Security and commonly used for fraud. To some people they don’t need to see a Yellow Padlock on the browser, one on the webpage is enough, but fake.
Logged

What you see isn’t what you always get!
Tarantela
Comodo's Hero
*****
Offline Offline

Posts: 251


Such a cute lizard.


« Reply #2 on: June 26, 2009, 03:42:21 AM »

Melih you have explained the problem in very simple and understandable vocabulary and
i have learned something new today.
I have a suggestion for the download of CIS and it is to make the personalfirewall.comodo.com
a secure green padlock site.
It would be an assurance that Comodo company is thinking about user safety when they
download CIS or any other Comodo product.
Logged

Peace and love , peace and love!
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2725


Follow the White Rabbit...


« Reply #3 on: June 26, 2009, 03:53:40 AM »

I have to wonder how many 'normal' users know what the padlock means, assuming they even see it!

The underlying PKI, for now, is sound, but we need something much more obvious and enlightening about any 'secure' connection we make, especially if it involves the transmission of confidential data.

 


Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #4 on: June 26, 2009, 03:55:25 AM »

Lol, I didn't even know that the yellow padlock was there for that reason .  Well, at least I know it now  Roll Eyes

Xan
Logged

Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2725


Follow the White Rabbit...


« Reply #5 on: June 26, 2009, 04:04:37 AM »

Xan, step into my office, we need to have a conversation ;p
Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
J2897
Comodo's Hero
*****
Offline Offline

Posts: 224


Limted User Account Enforcer


WWW
« Reply #6 on: June 26, 2009, 11:08:27 AM »

That video was nice and clear; easy to understand. But if anyone missed it:

SSL (the Padlock) means that the Connection (from 'you' to 'the site' you are on) is Encrypted; but that's all it means.

It does NOT mean that the Site Owners are 'Legitimate' or 'Trust Worthy'.
Logged

Endymion
Comodo's Hero
*****
Offline Offline

Posts: 883


Reality is subordinate to perception


WWW
« Reply #7 on: June 26, 2009, 11:13:08 AM »

IMHO in some cases even fairly limited guarantees may be enough, though this may be arguable.


Indeed despite providing different trust levels DV and OV certs are equally represented with the same padlock.

eg: some blog,forum and alike services that require user to provide not much than an email  use ssl certs :

https://forums.weather.com cert is an OV (Organization validation) one but https://help.ubuntu.com/community, https://blogs.secondlife.com/ and https://twitter.com/ are DV (Domain Validation) certs.



Whenever the padlock could lead to implicitly assume more guarantees than those actually implied is no negligible concern, I'm among the lines of those who are not totally against DV certs although I agree that in some scenarios DV certs are not reliable enough.


eg: https://www.createspace.com/ provide a shopping cart but use a DV cert whereas it is not possible to confirm its owner through whois (contact address use a 3rd party  privacy service)

Indeed www.createspace.com is an Amazon subsidiary http://www.amazon.com/gp/help/customer/display.html?nodeId=15015781

But there is no direct way to confirm the organization like there would be for EV or OV certs.
« Last Edit: June 26, 2009, 03:06:20 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #8 on: June 26, 2009, 11:43:21 AM »

Xan, step into my office, we need to have a conversation ;p
Sure where do we meet ?

Xan
Logged

harmony
Newbie
*
Offline Offline

Posts: 7



WWW
« Reply #9 on: June 28, 2009, 10:18:11 PM »

Dangerous Validation! Ha...very Newsful, Melih. Thnx.

Kind regards,
Srikanth
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 8216



WWW
« Reply #10 on: June 29, 2009, 10:19:30 AM »

IMHO in some cases even fairly limited guarantees may be enough, though this may be arguable.


Indeed despite providing different trust levels DV and OV certs are equally represented with the same padlock.

eg: some blog,forum and alike services that require user to provide not much than an email  use ssl certs :

https://forums.weather.com cert is an OV (Organization validation) one but https://help.ubuntu.com/community, https://blogs.secondlife.com/ and https://twitter.com/ are DV (Domain Validation) certs.



Whenever the padlock could lead to implicitly assume more guarantees than those actually implied is no negligible concern, I'm among the lines of those who are not totally against DV certs although I agree that in some scenarios DV certs are not reliable enough.


eg: https://www.createspace.com/ provide a shopping cart but use a DV cert whereas it is not possible to confirm its owner through whois (contact address use a 3rd party  privacy service)

Indeed www.createspace.com is an Amazon subsidiary http://www.amazon.com/gp/help/customer/display.html?nodeId=15015781

But there is no direct way to confirm the organization like there would be for EV or OV certs.

Indeed there are some uses of DV, although fairly limited.

DVs are being used in ecommerce to "establish trust" today. This is wrong, VERY wrong. DV should NOT be used for establishing trust, because there is no trust component in a DV certificate.

Melih
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #11 on: June 29, 2009, 01:27:08 PM »

Just a question Melih, Why dont the forums have a green bar insted of just the Yellow Padlock.
Logged

What you see isn’t what you always get!
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 8216



WWW
« Reply #12 on: June 29, 2009, 02:09:53 PM »

Just a question Melih, Why dont the forums have a green bar insted of just the Yellow Padlock.

because we havent' put an EV cert there..
i guess we should...

Melih
Logged

eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #13 on: June 30, 2009, 02:57:34 AM »

because we havent' put an EV cert there..
i guess we should...

Melih
That would be better, yes Smiley

Xan
Logged

zyrelle27
Newbie
*
Offline Offline

Posts: 17

"Keep Moving Forward..."


« Reply #14 on: July 01, 2009, 02:05:07 AM »

Wow. Now I know what those yellow padlock is for... I didn't even know what it means, before I just thought that it's some sort of a secure connection between me (my browser) and the site I'm trying to enter.

New knowledge installed.  Grin

Thanks Melih.
Logged
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.046 seconds with 18 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com