Nope, this isn’t the HTTPS validated Str ipe website you think it is

Channel:
Subscribers:
957
Published on ● Video Link: https://www.youtube.com/watch?v=86EvaMon05E



Duration: 3:27
1 views
0


Nope, this isn’t the HTTPS-validated Str.ipe website you think it is.
For a decade, some security professionals have held out extended validation certificates as an innovation in website authentication because they require the person applying for the credential to undergo legal vetting. That's a step up from less stringent domain validation that requires applicants to merely demonstrate control over the site's Internet name. Now, a researcher has shown how EV certificates can be used to trick people into trusting scam sites, particularly when targets are using Apple's Safari browser.

Researcher Ian Carroll filed the necessary paperwork to incorporate a business called Stripe Inc. He then used the legal entity to apply for an EV certificate to authenticate the Web page https://stripe.ian.sh/. When viewed in the address bar, the page looks eerily similar to https://stripe.com/, the online payments service that also authenticates itself using an EV certificate issued to Stripe Inc.

The demonstration is concerning because many security professionals counsel end users to look for EV certificates when trying to tell if a site such as https://www.paypal.com is an authentic Web property rather than a fly-by-night look-alike page that's out to steal passwords. But as Carroll's page shows, EV certs can also be used to trick end users into thinking a page has connections to a trusted service or business when in fact no such connection exists. The false impression can be especially convincing when end users use Apple's Safari browser because it often strips out the domain name in the address bar, leaving only the name of the legal entity that obtained the EV certificate.

"With enough mouse clicks, you may be able to open a system certificate viewer or get your browser to show you the city and state," Carroll wrote. "But neither of these are helpful to a typical user, and they will likely just blindly trust the bright green indicator."




Other Videos By Tech House


2017-12-11Ataribox preorders and crowdfunding campaign open on December 14
2017-12-11Goo gle's AR Stickers are here, and photos will never be the same again
2017-12-11American Express and MasterCard are quietly k illing one of the most annoying things about
2017-12-11The latest $2 billion rights deal between the NFL and Verizon doesn't seem to be good for
2017-12-11Netflix says 53 of its viewers have been watching 'A Christmas Prince' every single day for
2017-12-11Net neutrality repeal based on false descr iption of Internet, inventors say
2017-12-11Watch us test PlayerUnknown’s Battlegrounds on Xbox One X
2017-12-11Apple's purchase of Shazam goes well beyond music as it adds data, algorithm knowhow and talent
2017-12-11Apple Shares New Ads Highlighting iPhone X Face ID and Portrait Lighting
2017-12-11There is a d ead phone epidemic Solve it with this b attery pack that's $80 off
2017-12-11Nope, this isn’t the HTTPS validated Str ipe website you think it is
2017-12-11Geelong, the restart capital of Australia
2017-12-11Robots will definitely take our jobs but they might give us better lives in exchange
2017-12-1113 Tips for Photographing Holiday Lights
2017-12-11Voluntary net neutrality will protect consumers after repeal, FCC claims
2017-12-11Incredible satellite photos of Southern California's wildfires show the disaster's evolution
2017-12-11Peter Thiel is betting on magic mushrooms to treat depression — and he's not the only
2017-12-11Game Boss interview New CEO Pete Hawley will focus Telltale on its core strengths
2017-12-11A tiny British startup got 26 million views for its first VR experience — now it's made a
2017-12-11Bitcoin bull Tom Lee has identified 12 stocks that are perfect if you don’t want to own it
2017-12-11Here's why Boeing 747s have a giant hump in the front



Tags:
Nope
this
isn’t
the
HTTPS-validated
Str.ipe
website
you
think
it
is
this isn’t the HTTPS-validated Str.ipe website you think it is