Re: [FORGED] Re: Germany's cyber-security agency [BSI] recommends Firefox as most secure browser

2019-10-20 Thread Daniel Marschall via dev-security-policy
I think the only really important purpose of OV and EV over DV is that they are visible on the first sight. Nobody opens the X.509 file to look at the EKU OIDs or the subject DN. The requirement could just say that x.509 must be supported, but they do differentiale DV, OV and EV. ___

Re: [FORGED] Re: Germany's cyber-security agency [BSI] recommends Firefox as most secure browser

2019-10-18 Thread Paul Walsh via dev-security-policy
On Oct 18, 2019, at 6:39 PM, Peter Bowen wrote: > >  >> On Fri, Oct 18, 2019 at 6:31 PM Peter Gutmann via dev-security-policy >> wrote: > >> Paul Walsh via dev-security-policy >> writes: >> >> >I have no evidence to prove what I’m about to say, but I *suspect* that the >> >people at BSI sp

Re: [FORGED] Re: Germany's cyber-security agency [BSI] recommends Firefox as most secure browser

2019-10-18 Thread Paul Walsh via dev-security-policy
On Oct 18, 2019, at 6:31 PM, Peter Gutmann wrote: > > Paul Walsh via dev-security-policy > writes: > >> I have no evidence to prove what I’m about to say, but I *suspect* that the >> people at BSI specified “EV” over the use of other terms because of the >> consumer-visible UI associated with

Re: [FORGED] Re: Germany's cyber-security agency [BSI] recommends Firefox as most secure browser

2019-10-18 Thread Peter Bowen via dev-security-policy
On Fri, Oct 18, 2019 at 6:31 PM Peter Gutmann via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Paul Walsh via dev-security-policy > writes: > > >I have no evidence to prove what I’m about to say, but I *suspect* that > the > >people at BSI specified “EV” over the use of o

Re: [FORGED] Re: Germany's cyber-security agency [BSI] recommends Firefox as most secure browser

2019-10-18 Thread Peter Gutmann via dev-security-policy
Paul Walsh via dev-security-policy writes: >I have no evidence to prove what I’m about to say, but I *suspect* that the >people at BSI specified “EV” over the use of other terms because of the >consumer-visible UI associated with EV (I might be wrong). Except that, just like your claims about M