“What is the blue padlock for? What type of validation?”
In Firefox 3.5 address bar -
Grey = Not encrypted or only partially encrypted content on page.
Blue = DV type cert, encrypted content, site ID not ensured.
Green = EV cert, encrypted content and ensured ownership ID.
So, Comodo now has EV cert on Forum. Shows Green on any page without external links.
But like as noted above this particular page shows only Grey in address bar, and Red exclamation on Padlock icon. Because of the link to imageshack or someones sig.
Firefox can’t display Green due to page containing this unauthenticated content.
Now if I could get my bank to go Green/EV. Thank Gawd Comodo for VEngine.
Having read this topic it still seems that a lot of people don’t know what the padlock
or colours the browser put up actually mean.
Is anything being done by browser providers to highlight to ‘joe public’, in simple terms, what they
see when browsing secure pages?
ie, maybe a balloon that opens up on secure pages over the padlock or colour bar and asks the
user ‘know what this is?’ or ‘tell me more about this’.
An option that can be activated or de-activated by the user.
The visible indications of security are all well and good, but not if the person browsing doesn’t understand
what they are seeing.
So, my point is ‘user education’…anything in the pipeline to educate the user?
That is without them having to install yet more add-ons.
I’m pretty sure that when I get to an encrypted page my browser offers me a tiny “what does this mean?” popup. But at that point I am so focused on completing my encrypted session that I swat it down. Next time I see one I’ll actually read it and report back.
Well, encryption without authentication is useless. Encryption is about allowing only the intendent receipient to read the message. If you don’t know who the recipient is then you could be encrypting it for the fraudster and you wouldn’t know…so without authentication encryption becomes useless.
I guess there is no browser which natively distinguish OV-SSL from DV-SSL certs.
Even firefox show the same blue bar of DV ssl certs for https://www.microsoft.com/ whose cert ought to be an OV one as Organizational info about Microsoft is included in the certificate details thus allowing users to confirm the identity of the recipient ???
Neither McAfee Advisor nor Norton Safe Web can recognize it
Comodo’s Site Inspector (CSI), I may say it again here in the forum unfortunately as usual just goes into deep Nirvana cycle.
I have an impression that the thing (CSI) is not working properly at all… (that’s either Ok on bad sites or this “cycling” behaviour - waiting /done forever & no result)
Would be nice if Vengine would do something … ut probably that is !ot! here
… haven’t checked “clydesdalebplc” …gotta run now :o
So if you went to [ https://www.e-abbey.com/bankhome/ ] with Verification Engine installed, you wouldn’t see any Alert or Warning. But if you went to the real/genuine site with Verification Engine installed, your screen’s border will light up in Green… White List Technology beats Black List Technology like Scissors beats Paper.
Thanks for reply
and the note …interestingly enough i’m aware of that , but honestly I have to reread the thread cause I’m not sure why I mentioned that in the context … 88)
most likely I was really in a hurry, when saying that I “gotta run” … & what “…ut” means in my text? - I have no idea ;D