By the following snippet referring to a Slashdot
post, it seems that someone registered a company
called "Click Yes To Continue" and then proceeded
to buy a cert and create some softwhere!



-------- Original Message --------


For once the discussion on Slashdot, at
is not entirely noise. The most interesting post is this one:

# This is what Verisign answered when I asked them the same question last
# year (and then refused the stupid automated reply):

   In response to your email, when this company submitted their request for
   a digital certificate, we followed our standard authenticiation &
   verification policies to make sure of the following:

   1. That the company, Click Yes To Continue, is indeed a legitimate
      company and has the right to conduct business under this company
      name, which was confirmed using an online, 3rd party web site for
      validating companies located in Canada.
   2. Received a valid phone bill from the company, in which we used to
      call the company back & confirm the order.

   Please note that when a company obtaina code signing certificate, we
   DO NOT validate their code, as the customer has to agree to our
   certificate policies before even submitting their requets online.

   Therefore, we did not issue a certificate to a 'fake company'. However,
   we will forward your email to our internal security department and
   Verisign Lawyers to see if this company is indeed distributing
   fraudulent code using a certificate obtained through Verisign.

# Obviously, nothing happened afterwards.


cap-talk mailing list

News and views on what matters in finance+crypto:

mozilla-crypto mailing list

Reply via email to