<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft / Verisign SSL Scam</title>
	<atom:link href="http://www.infosecpodcast.com/2006/10/microsoft-verisign-ssl-scam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecpodcast.com/2006/10/microsoft-verisign-ssl-scam/</link>
	<description>Information Security related news, opinions and ramblings</description>
	<lastBuildDate>Sun, 25 Jul 2010 08:44:08 -0600</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Chris Harrington</title>
		<link>http://www.infosecpodcast.com/2006/10/microsoft-verisign-ssl-scam/comment-page-1/#comment-1166</link>
		<dc:creator>Chris Harrington</dc:creator>
		<pubDate>Fri, 27 Oct 2006 19:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecpodcast.com/industry-news/2006/10/microsoft-verisign-ssl-scam/#comment-1166</guid>
		<description>Eric,

Thank you for the corrections on 1 and 2. I will update them shortly. As for the cost of certificates, EV will be more according to the Verisign rep I spoke with. This rep also said they will continue to sell both types of certificates. Why would they do that if the price was the same? EV is going to be a value add sell. I never said there was a requirement to sell for more, but an opportunity to do so.

Thanks again for the corrections.</description>
		<content:encoded><![CDATA[<p>Eric,</p>
<p>Thank you for the corrections on 1 and 2. I will update them shortly. As for the cost of certificates, EV will be more according to the Verisign rep I spoke with. This rep also said they will continue to sell both types of certificates. Why would they do that if the price was the same? EV is going to be a value add sell. I never said there was a requirement to sell for more, but an opportunity to do so.</p>
<p>Thanks again for the corrections.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EricLaw [MSFT]</title>
		<link>http://www.infosecpodcast.com/2006/10/microsoft-verisign-ssl-scam/comment-page-1/#comment-1165</link>
		<dc:creator>EricLaw [MSFT]</dc:creator>
		<pubDate>Fri, 27 Oct 2006 19:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecpodcast.com/industry-news/2006/10/microsoft-verisign-ssl-scam/#comment-1165</guid>
		<description>There are several incorrect claims here. 

1&gt; Untrusted self-signed certificates show as Certificate Error, the address bar is red, and the user is stopped by a blocking page.

To be clear, there&#039;s no &quot;Suspicious Website&quot; page you&#039;re talking about comes from the fact that this is a phishing webpage coming from an IP address.  HTTPS isn&#039;t at all involved here.

2&gt; Non-Extended-Validation certificates do not show in Yellow.  The address bar is white and the lock icon is shown.  

As for the idea that EV certificates are simply &quot;more expensive&quot;, that&#039;s not true either.  There&#039;s no particular criteria that EV certificates be more expensive.  The criteria is that the CA must follow a well-defined vetting process against the organization requesting the certificate.</description>
		<content:encoded><![CDATA[<p>There are several incorrect claims here. </p>
<p>1&gt; Untrusted self-signed certificates show as Certificate Error, the address bar is red, and the user is stopped by a blocking page.</p>
<p>To be clear, there&#8217;s no &#8220;Suspicious Website&#8221; page you&#8217;re talking about comes from the fact that this is a phishing webpage coming from an IP address.  HTTPS isn&#8217;t at all involved here.</p>
<p>2&gt; Non-Extended-Validation certificates do not show in Yellow.  The address bar is white and the lock icon is shown.  </p>
<p>As for the idea that EV certificates are simply &#8220;more expensive&#8221;, that&#8217;s not true either.  There&#8217;s no particular criteria that EV certificates be more expensive.  The criteria is that the CA must follow a well-defined vetting process against the organization requesting the certificate.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
