New issue
Advanced search Search tips

Issue 922666 link

Starred by 2 users

Issue metadata

Status: Untriaged
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Feature



Sign in to add a comment

Request: add indication of trust (Let'sEncrypt is not trusted to pay!)

Reported by bau...@gmail.com, Jan 16 (6 days ago)

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36

Steps to reproduce the problem:
1. open https://www martensvente com
2. if you want to go all the way; creation of an account, validation of a basket, and payment

Let'sEncrypt is not trusted to pay!

Most users have been stuck on the fact that a padlock means that the site is secure, and does not pose the question of trust.
Chrome no longer displays the green banner for EV certificates, but writes the name in gray as the address. It's easy now to secure a website to steal the credit card number with let'sencrypt without needing to provide a piece of ID (formerly indispensable even with SSLstart). And chrome not display certification authority easily.

  Will it be possible to set up a confidence indicator? Depending on the nature of the certificate ?

What is the expected behavior?
Trust 0 with Let'sEncrypt.
High level for EV cert...

What went wrong?
Many people are being fooled since it's easy to get a valid certificate. 

Did this work before? N/A 

Chrome version: 71.0.3578.98  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

it worked before, because even to obtain a free certificate, it was necessary to provide a piece of identity. So most sites did not use it. It was easy to find a trusted site; an easy scam. Many communicated to the fact that a secure site and by extension of trust had a padlock.
 
20190116.png
87.4 KB View Download

Comment 1 Deleted

Comment 2 by bau...@gmail.com, Jan 16 (6 days ago)

bad capture attached; more complete this one:

Please note: This is a request, not a bug.
20190116.png
110 KB View Download

Comment 3 by viswa.karala@chromium.org, Jan 17 (6 days ago)

Labels: Needs-Triage-M71

Comment 4 by viswa.karala@chromium.org, Jan 17 (5 days ago)

Cc: viswa.karala@chromium.org
Labels: -Type-Bug Triaged-ET Target-73 M-73 FoundIn-71 FoundIn-73 FoundIn-72 OS-Linux OS-Mac Type-Feature
Status: Untriaged (was: Unconfirmed)
Thanks for filing the issue!

@Reporter: As per comment#2, issue seems to be a Feature request, hence marking it as Untriaed.

Thanks!

Comment 5 by bau...@gmail.com, Jan 18 (4 days ago)

another example for the request for improved security and display: Chrome no longer displays the protocol, so we see sites "not secure" but it is normal however we would have liked that HTTP is displayed in order to identify the cause quickly.
Thanks

Sign in to add a comment