Podcast
Root Causes 78: Extended Validation Certificates and the Dark Web


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
March 26, 2020
New research presented at RSA Security Expo indicates that at least one party is using online criminal marketplaces to sell a package of a newly-created business and at least one Extended Validation (EV) SSL certificate to go with it. Join our hosts as they explain what the research says and talk about the potential criminal use cases for a bundle like this one.
Podcast Transcript
Lightly edited for flow and brevity.
Wow, Tim. So, you know, I can tell you in the jurisdiction where I live, it really wouldn't be feasible or not even close because of the expenses involved with doing some of what you just said. So, was there something in the paper that explains the ease, the lack of friction, lack of cost.
And so, you know, in reality, this would have to be a very unusual use case where this thing was being used, especially, again, since I can't go get a cert for, you know, a high value, high visibility target, since I can't necessarily go get a cert for Citibank, you got to say, well, okay, what is that scenario where it's important to have the green address bar, but it doesn't matter what it's called and it's worth that investment? I don't know it’s kind of tough.

