MysteryFCM wrote:
The other vendors aren't being let off with this, nor are we pretending they aren't in the same position - but they aren't selling or developing security software either.
I personally can't see the relation with Comodo selling other security software with them selling DV certs, or either Comodo's giving off free security software. Users will be fooled by the
yellow padlock whether its from Comodo or any others, independent of whether they use or even just aware of Comodo's selling of other security product.
MysteryFCM wrote:
Comodo cannot use the excuse that other cert vendors are doing it - this simply won't wash with us. I can't speak on percentages of the market they hold as I don't know that, and won't pretend to, but if they want to be taken seriously, and seen to be taking action instead of sitting back and raking in the $$ from the malicious guys - they need to stand up and stop issuing them - period, irrespective of whether it's 10%, 20% or 100% of the market they hold.
I think Melih's point is that research such as yours should be more focus on the bigger DV provider and not to them as he sees it. Just my thinking.
But you're right, they should do their share too. I saw on other forum and I quoted on my previous post that Melih already suggested to other vendors to set a standard for DV issuance which they (other vendor) opposed. If that is true, isn't it better if we help him (Melih) in pushing other vendors to do as he propose? Maybe doing some (or more) research focusing on those other vendors would make them see the point that the current DV certs issuance has security hole. I quote again Melih below.
Quote:
Coming to now, Comodo has proposed a minimum standard to the CABForum for DV. Because today there is no standard for how to issue Yellow padlock. You see I believe a Certification Authority must Certify Identity, otherwise whats the point. So we are pushing for a standard, but we are getting resistance from the "DV Market Leaders" Smiley. Of course "DV Market Leaders" have Legal Monies to spend if browser people force a change on them. So it has be done amicably..but they resist!
So that's the story!
I think we need to educate users and get them to demand better standards from their browsers and be aware of DV certs (asking for too much but hey)..
We as Comodo will continue to push for minimum standards thru the CABForum and everyone should write to their Browser vendors and demand that they should improve the DV SSL standards.
Hope this clarifies, if not pls feel free to ask.
thanks
Melih