Monday, June 30, 2025
Germany Latest News
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe
No Result
View All Result
Germany Latest News

Nope, this isn’t the HTTPS-validated Stripe website you think it is

by The Editor
December 12, 2017
in Tech
0
Nope, this isn’t the HTTPS-validated Stripe website you think it is
EnlargeIan Carroll

For a decade, some security professionals have held out extended validation certificates as an innovation in website authentication because they require the person applying for the credential to undergo legal vetting. That's a step up from less stringent domain validation that requires applicants to merely demonstrate control over the site's Internet name. Now, a researcher has shown how EV certificates can be used to trick people into trusting scam sites, particularly when targets are using Apple's Safari browser.

Researcher Ian Carroll filed the necessary paperwork to incorporate a business called Stripe Inc. He then used the legal entity to apply for an EV certificate to authenticate the Web page https://stripe.ian.sh/. When viewed in the address bar, the page looks eerily similar to https://stripe.com/, the online payments service that also authenticates itself using an EV certificate issued to Stripe Inc.

Related posts

What Are the Pros and Cons of Sperm Freezing Technology?

What Are the Pros and Cons of Sperm Freezing Technology?

September 8, 2023
How Tech Partnerships Can Keep the E-Commerce Boom Going?

How Tech Partnerships Can Keep the E-Commerce Boom Going?

September 8, 2023

The demonstration is concerning because many security professionals counsel end users to look for EV certificates when trying to tell if a site such as https://www.paypal.com is an authentic Web property rather than a fly-by-night look-alike page that's out to steal passwords. But as Carroll's page shows, EV certs can also be used to trick end users into thinking a page has connections to a trusted service or business when in fact no such connection exists. The false impression can be especially convincing when end users use Apple's Safari browser because it often strips out the domain name in the address bar, leaving only the name of the legal entity that obtained the EV certificate.

Enlarge

"With enough mouse clicks, you may be able to open a system certificate viewer or get your browser to show you the city and state," Carroll wrote. "But neither of these are helpful to a typical user, and they will likely just blindly trust the bright green indicator."

Carroll's demonstration comes three months after researcher James Burton exposed a different way EV certificates can be used to trick end users. He established a business named "Identity Verified" and showed how the resulting EV certificate might be used to add the air of authenticity a scam site. Both Carroll and Burton said little effort was necessary to create the legal entities. Carroll said the demo cost $177: $100 in incorporation expenses and $77 for the certificate.

The demonstrations are generating productive discussions among developers about the way EV certificates should be treated in browser user interfaces. Security professionals are also openly discussing whether certificate rules should be modified to prevent these types of cases.

For the time being, people should remember that EV certificates aren't automatically a panacea for online fraud. In some cases, certificates could make an otherwise obvious scam site seem legitimate. When in doubt, end users should carefully inspect the certificate and ensure it was issued to the operator of the trusted site.

Original Article

Ars Technica

The post Nope, this isn’t the HTTPS-validated Stripe website you think it is appeared first on News Wire Now.

Previous Post

Efforts to economically link China and Pakistan hit a road block

Next Post

WATCH: Fordham Students Kicked Out of On-Campus Coffee Shop over ‘MAGA’ Hats

Next Post
WATCH: Fordham Students Kicked Out of On-Campus Coffee Shop over ‘MAGA’ Hats

WATCH: Fordham Students Kicked Out of On-Campus Coffee Shop over ‘MAGA’ Hats

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

New York City Council passes sweeping police reform bills

New York City Council passes sweeping police reform bills

5 years ago
Ronaldo aging like ‘port wine’ at 4th World Cup

Ronaldo aging like ‘port wine’ at 4th World Cup

7 years ago
Apple AirPods Pro 2 Release Date Rumours and Leaks

Apple AirPods Pro 2 Release Date Rumours and Leaks

3 years ago
Brisbane eye finals berth after gallant defeat of Hawthorn

Brisbane eye finals berth after gallant defeat of Hawthorn

6 years ago

FOLLOW US

  • 139 Followers
  • 87.2k Followers
  • 202k Subscribers

BROWSE BY CATEGORIES

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • AI
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

BROWSE BY TOPICS

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
No Result
View All Result

Recent Posts

  • AI Girlfriends as Creative Writing Partners
  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities
  • What is a Mail Order Wife?

Categories

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • AI
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Tags

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
Federal Government focuses on “integrated security”
latest news

Federal Government focuses on “integrated security”

by The Editor
June 14, 2023
0

Berlin (dpa) – The Federal Government is responding to the challenges of an increasingly unstable world order by means of a “policy...

Read more

Recent News

  • AI Girlfriends as Creative Writing Partners
  • OnlyFans Platform Analysis
  • How to Day German Fashion

Category

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • AI
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Recent News

AI Girlfriends as Creative Writing Partners

May 30, 2025

OnlyFans Platform Analysis

June 12, 2024
  • About
  • Advertise
  • Careers
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.