Request: add indication of trust (Let'sEncrypt is not trusted to pay!)
Reported by
bau...@gmail.com,
Jan 16
(6 days ago)
|
|||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 Steps to reproduce the problem: 1. open https://www martensvente com 2. if you want to go all the way; creation of an account, validation of a basket, and payment Let'sEncrypt is not trusted to pay! Most users have been stuck on the fact that a padlock means that the site is secure, and does not pose the question of trust. Chrome no longer displays the green banner for EV certificates, but writes the name in gray as the address. It's easy now to secure a website to steal the credit card number with let'sencrypt without needing to provide a piece of ID (formerly indispensable even with SSLstart). And chrome not display certification authority easily. Will it be possible to set up a confidence indicator? Depending on the nature of the certificate ? What is the expected behavior? Trust 0 with Let'sEncrypt. High level for EV cert... What went wrong? Many people are being fooled since it's easy to get a valid certificate. Did this work before? N/A Chrome version: 71.0.3578.98 Channel: stable OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: it worked before, because even to obtain a free certificate, it was necessary to provide a piece of identity. So most sites did not use it. It was easy to find a trusted site; an easy scam. Many communicated to the fact that a secure site and by extension of trust had a padlock.
,
Jan 16
(6 days ago)
bad capture attached; more complete this one: Please note: This is a request, not a bug.
,
Jan 17
(6 days ago)
,
Jan 17
(5 days ago)
Thanks for filing the issue! @Reporter: As per comment#2, issue seems to be a Feature request, hence marking it as Untriaed. Thanks!
,
Jan 18
(4 days ago)
another example for the request for improved security and display: Chrome no longer displays the protocol, so we see sites "not secure" but it is normal however we would have liked that HTTP is displayed in order to identify the cause quickly. Thanks |
|||
►
Sign in to add a comment |
|||
Comment 1 Deleted