> OK, I'll try one last time to see if you are willing to share Google > information that you have with this group on the question at hand (Do browser > phishing filters and anti-virus apps use EV data in their anti-phishing > algorithms). > > This is super easy, and doesn't even require you to do any work, like > contacting Google Safe Browsing and asking them to participate in this > conversation. > > Here's the question, and all I'm asking you to do is answer "Yes," "No," or > "I Don't Know" > > **Based on your personal knowledge, does Google Safe Browsing use any EV > certificate Subject information in its anti-phishing algorithms?** > > This will be useful information to everyone on this list. > > Thanks for your cooperation.
I want to withdraw the question above that I posed to Ryan - I posted this last night in frustration, but I was wrong to put someone on the spot like that. I'll just reiterate my point and then drop the subject. EV certificate subject information is used by anti-phishing services and browser phishing filters, and it would be a loss to the security ecosystem if this EV data disappears (meaning that the decision on removal of the EV UI has greater repercussions than just whether or not users can tell in the primary UI if their website does or does not have any confirmed identity information). I hope Mozilla will pivot to a redesigned EV UI (instead of removing it entirely) like the Apple UI (green lock and URL when EV identity is present, black lock symbol/UI for anonymous sites). That solution (1) seems to satisfy the concerns Mozilla started with (that users don't understand specific ownership data presently shown in the Firefox UI), (2) allows users to know the identity status of a website before they enter their password or credit card number, (3) would allow for easy user training on the meaning of the new Firefox UI, (4) would continue to incentivize enterprise website owners to continue using EV certificates, thereby continuing to populate the security ecosystem with very useful data related to website domains that can be used for anti-phishing purposes, (5) work very well in a mobile environment where space is limited, (6) probably represent a modest engineering effort to make the change and maintain it, and (7) start the process of creating a common UI among different browsers (Apple is there already), which can only be good for user security. _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

