New issue
Advanced search Search tips

Issue 792931 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 3
Type: Feature
Team-Security-UX



Sign in to add a comment

Display Issuer name after Secure in address bar for DV certificates.

Reported by skuldw...@gmail.com, Dec 7 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36

Steps to reproduce the problem:
(Feature request)

What is the expected behavior?
On secure sites the start of he address bar is: "🔒 Secure"
ideally it should be "🔒 Secure (Let's Encrypt)" or "🔒 Secure (Comodo)" and so on.

If you look at the Issuer details of a certificate you'll see that it has a "O" (Organisation) value of the issuer.
This is very terse, and should be shown within parentheses. 

What went wrong?
There is no easy way to see the issuer of a certificate for DV (domain validated) certificates.

Did this work before? N/A 

Chrome version: 62.0.3202.94  Channel: n/a
OS Version: 10.0
Flash Version: 

This idea if implemented should educate users automatically. Once they start to see Let's Encrypt, or Comodo in parentheses for multiple sites they'll start to understand that they are related to the security of a site.

Soon they'll know to trust theses certs more and CA brand knowledge will increase. Sites or companies that do not want the CA name shown can get a EV cert instead.

Right now if you went to youtube.com and if my suggested have been implemented you would see the address bar as such: "🔒 Secure (Google Inc) https://youtube.com/"

This would automatically train the user to understand that "Google Inc" is somehow providing the secure communication with youtube (technically Google Inc is validating that you are connected to youtube.com but most users won't think that way).

This would also reveal situations where a antivirus is intercepting traffic as those certs would possibly have a different O value for the issuer. The average user may not think too much if a site changed from having (Comodo Inc) to (DigiCert Inc) in the address bar, but more tech savvy users and IT guys would quickly see that something is off.
 
Cc: elawrence@chromium.org
Components: UI>Browser>Omnibox>SecurityIndicators>VerboseChip
Labels: -Type-Bug-Security -Pri-2 -Restrict-View-SecurityTeam Pri-3 Type-Feature
Summary: Display Issuer name after Secure in address bar for DV certificates. (was: Display organization name after Secure in address bar for DV certificates.)
This is a feature request. I believe it has merit, but it also entails significant tradeoffs because repurposing strings never intended for use in this manner is inherently complex.

We briefly showed the issuer as a tooltip on the "Certificate" link in PageInfo (https://textslashplain.com/2017/05/02/inspecting-certificates-in-chrome/) but that seems to have regressed recently.
Status: Untriaged (was: Unconfirmed)
Agree with #1. 
I'm inclined to mark it as Won'tFix. 
I'll wait till the end of this week. If no one object, I'll mark it as Won'tFix then.
+1 to WontFix -- I don't think the issuer is of sufficient general interest that taking up this space is warranted, and there's a user confusion risk of associating the current page with the issuer.  As long as this information is easily accessible elsewhere, I'd rather not show it by default.
Status: WontFix (was: Untriaged)

Sign in to add a comment