On Thursday, April 20, 2017 at 4:03:36 PM UTC+3, Gervase Markham wrote:
> Mozilla also doesn't believe that it's the job of CAs to police phishing

CAs should police as long as the browser gives positive reinforcement to the 
end-users when they access a [phishing] site.

There were suggestions in the past to remove the 'green lock' for DV/OV 
certificates. Once this is done, I believe CAs that generates those certs can 
stop "policing".
_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy
          • Re: Remov... Ryan Sleevi via dev-security-policy
            • Re: ... Peter Kurrasch via dev-security-policy
              • ... Ryan Sleevi via dev-security-policy
              • ... Peter Kurrasch via dev-security-policy
          • Re: Remov... okaphone.elektronika--- via dev-security-policy
            • Re: ... Ryan Sleevi via dev-security-policy
            • Re: ... okaphone.elektronika--- via dev-security-policy
              • ... Ryan Sleevi via dev-security-policy
              • ... okaphone.elektronika--- via dev-security-policy
  • Re: Removing "Wildcar... Gervase Markham via dev-security-policy
  • Re: Removing "Wildcar... Itzhak Daniel via dev-security-policy

Reply via email to