Google Inc. drop the separate designation of EV certificates in Chrome. Previously, for websites with such certificates, the name of the company verified by the certificate authority was displayed in the address bar, but now for these sitesthe same indicator of a secure connection will be displayed as for domain-validated certificates. A study conducted by Google showed that the previously used indicator for EV certificates did not provide the expected protection for users who did not pay attention to the difference and did not use it when making decisions about entering confidential data on websites. The research indicated that
85% of users were not deterred from entering their credentials due to the presence of the URL "accounts.google.com.amp.tinyurl.com" instead of "accounts.google.com" in the address bar, as long as the page displayed the typical Google interface.
To instill trust in a website, it turned out to be sufficient for most users if the page resembled the original. As a result, the conclusion was made that positive security indicators are ineffective and focus should be placed on providing clear warnings about problems. For example, a similar approach is used for HTTP connections, which are explicitly marked as insecure. Additionally, the information displayed for EV certificates takes up too much space in the address bar, can lead to additional confusion when seeing the company name in the browser interface, and also violates the principle of product neutrality.
The information displayed for EV certificates takes up too much space in the address bar, can cause additional confusion when seeing the company name in the browser interface, and also violates the principle of product neutrality.
The information displayed for EV certificates takes up too much space in the address bar, may lead to additional confusion when seeing the company name in the browser interface, and also violates the principle of product neutrality. for phishing. For example, the certificate authority Symantec issued an EV certificate to the company 'Identity Verified', which misled users, especially when the actual name of the open domain did not fit in the address bar:
Addendum: Firefox developers will implement a similar solution and will not separately highlight EV certificates in the address bar starting from the release of Firefox 70. Firefox 70 will also include display of HTTPS and HTTP protocols in the address bar.
Source: opennet.ru
