{"id":617,"date":"2018-06-10T14:01:46","date_gmt":"2018-06-10T22:01:46","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=617"},"modified":"2018-06-30T10:13:06","modified_gmt":"2018-06-30T18:13:06","slug":"what-value-can-a-third-party-provide-users-when-browsing-the-web","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=617","title":{"rendered":"What value can a third-party provide users when browsing the web?"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">While at the CA\/Browser Forum I was asked by a friend if we wanted to replace EV with a new class of certificate what would that certificate look like?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">My response was that I would frame the question differently. The \u201creal\u201d question is what problems does a typical user have that a third-party with the strengths of a CA could help with?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With this in mind, you need to first\u00a0understand who this stereotypical user is, a software engineer may have different needs than a grocery store clerk. They may also have common needs, you won&#8217;t know that until you do research.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The only way to do reliable research on this topic is to actually work with those users to understand what their needs are. While this is much harder than it sounds due to biases introduced in such processes a real needs\u00a0analysis requires that you start here.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With that said, I suspect this exercise would show a broad swath of the target users is concerned with these questions:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Will I have a good experience working with the people behind the website?<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Do the people behind this website have a good reputation?<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Are the people behind this website experts in their craft?<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">How do I figure out how to reach a real human when and if I need to?<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">I would put those concerns into the context of the interaction they will have with the website (buying a product, downloading\u00a0software, etc).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With that understanding I would then try to understand what the strengths of the CA are, having been a CA for a long time I would say:<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400;\"> CAs are good at verifying claims relating to the subject of a certificate.<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\">I would then try to map the identified problems and strengths together to see what potential value the CA could provide that user.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Again the right thing to do is formally do those above explorations but for the purpose of this post I suspect these exercises would find that:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">When a user visits a website they may struggle to find out how to contact the sales\/support for that business,<\/span><\/li>\n<li>When a user visits a site for the first time it may be hard for them to determine what the companies true line of business is,<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">After a user previously visited a website and completed a transaction with it they sometimes need to contact that business after the fact and could be assisted in finding the right contact information,<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Before deciding to do a high-value transaction with a business, customers may want to find out the experience others have had with that business.<\/span><\/li>\n<\/ul>\n<p>Now, just because a user may have these problems and a CA may be able to help solve them, it does not mean the SSL indicator is the right place to help answer these questions. It just means that there is a problem and skills intersection.<\/p>\n<p>When, and how to solve this problem is another exercise altogether. Let&#8217;s explore EV for a second to give that some context.<\/p>\n<p><span style=\"font-weight: 400;\">Today if we assume the information in an EV certificate is correct (and not confusing see: <a href=\"https:\/\/stripe.ian.sh\/\">this<\/a>\u00a0and <a href=\"https:\/\/www.sirburton.com\/ev-phishing-final\/\">this<\/a>\u00a0for context) we can say it provides the answer to \u201cif I need to sue these people where do I tell my lawyer they are at?\u201d. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The problem with that is that you may not have that information when you need it. I say this because you typically need to sue someone after you completed a transaction with them not before. After the fact, you have no assurance that this information in the certificate will be available at the site you did the transaction with.\u00a0 The website may have gone away, they could have changed their certificate, or could some other change may have taken place that makes that information not readily available to you when you need it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In any event, the point of this post is to say CAs should not be asking what they can put into certificates but what problems users have that CAs are well suited to solve. Unless they start there they will not be solving a real problem, they will just be bolting more things onto a certificate and asking why browsers and users don\u2019t users see value in it.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While at the CA\/Browser Forum I was asked by a friend if we wanted to replace EV with a new class of certificate what would that certificate look like? My response was that I would frame the question differently. The \u201creal\u201d question is what problems does a typical user have that a third-party with the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,4],"tags":[47,6],"class_list":["post-617","post","type-post","status-publish","format-standard","hentry","category-security","category-thoughts","tag-ev","tag-ssl"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=617"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/617\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}