Re: Mozilla Policy Requirements CA Incidents

2019-10-14 Thread Ryan Sleevi via dev-security-policy
In the spirit of improving transparency, I've gone and filed https://github.com/mozilla/pkipolicy/issues/192 , which is specific to auditors. However, I want to highlight this model (the model used by the US Federal PKI), because it may also provide a roadmap for dealing with issues like this /

Re: Intent to Ship: Move Extended Validation Information out of the URL bar

2019-10-14 Thread carsten.mueller.gl--- via dev-security-policy
Already the screenshots of the report from 2016 on page 3 show why no normal user can recognize if a website was encrypted or if an EV certificate was in use. The browser manufacturers must agree on a uniform, easy-to-understand presentation of the security indicators and not change them every

Request received : Re: Intent to Ship: Move Extended Validation Information out of the URL bar ref:_00DU0Lfqj._5001v17KLYI:ref

2019-10-14 Thread Support TheFork via dev-security-policy
We have received your request 03530327 and it is being processed by our support team. To leave additional comments, reply to this email. ref:_00DU0Lfqj._5001v17KLYI:ref ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org

Re: Intent to Ship: Move Extended Validation Information out of the URL bar

2019-10-14 Thread Paul Walsh via dev-security-policy
I have two questions Ronald: 1. What should I look for? I just see a DV cert from Let’s Encrypt. 2. Why did you message the entire community about whatever it is you’ve found? Thanks, Paul Sent from my iPhone > On Oct 12, 2019, at 11:04 AM, Ronald Crane via dev-security-policy > wrote: >

Request received : Re: Intent to Ship: Move Extended Validation Information out of the URL bar ref:_00DU0Lfqj._5001v17KPuw:ref

2019-10-14 Thread Support TheFork via dev-security-policy
We have received your request 03531223 and it is being processed by our support team. To leave additional comments, reply to this email. ref:_00DU0Lfqj._5001v17KPuw:ref ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org

Request received : Re: Intent to Ship: Move Extended Validation Information out of the URL bar ref:_00DU0Lfqj._5001v17KQlt:ref

2019-10-14 Thread Support TheFork via dev-security-policy
We have received your request 03531375 and it is being processed by our support team. To leave additional comments, reply to this email. ref:_00DU0Lfqj._5001v17KQlt:ref ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org

Re: Intent to Ship: Move Extended Validation Information out of the URL bar

2019-10-14 Thread Ronald Crane via dev-security-policy
The finding is from public information that is relevant to the current value of EV certificates, which is a central part of this discussion. -R On 10/14/2019 11:10 AM, Paul Walsh via dev-security-policy wrote: I have two questions Ronald: 1. What should I look for? I just see a DV cert from