Web security ‘locks out’ legitimate sites

  • Associated Press
  • Monday, December 25, 2006 9:00pm
  • Business

NEW YORK – As an online shopper, Claudia Race knows she must look out for scams.

So as an Internet entrepreneur working out of her home in New Braunfels, Texas, Race wants to use all the tools available to assure customers they can trust the vacation-rentals service she is about to launch.

But because her small business is so new, Race said she might not qualify for the online seals of approval that Overstock.com Inc. and other larger, established companies are getting to instruct Microsoft Corp.’s Internet Explorer browser to display a green address bar for “safe” when people visit her site.

“It would put me at a disadvantage,” Race said. “I do not want anyone to have any questions, hesitate or have any fear factor. They have to know that I didn’t just go grab a logo from somewhere and stick it on my site. I want them to know I’m a legitimate business.”

What she’s seeking is an extended-validation certificate, a response to the plethora of “phishing” attacks in which scam artists try to steal sensitive data by mimicking the Web site of a large bank or merchant.

Once Microsoft activates the feature in version 7 of Internet Explorer in late January, a green bar will appear when the browser detects an EV certificate, usually during a transaction or login. The tool complements a newly launched filter that displays a red warning for known phishing sites and yellow for suspicious ones.

“EV does not authenticate that your plasma TV is going to show up or that it won’t have a crack through it,” said Tim Callan, director of product marketing for VeriSign Inc., which issued its first EV certificate to Overstock this month.

Rather, Callan said, the EV certificate will tell consumers that the business does exist and operates at the location it says it does.

That’s because VeriSign and its competitors will be required to perform extensive checks to verify that the business is legally recognized by a government agency and that the address registered for the certificate is valid, such as by matching it with a government filing or visiting the business in person.

Certificate issuers also must make sure that the company owns the domain name and that the individual requesting the certificate is authorized.

This prevents a scammer from registering overseas a domain name at “paypa1.com” – with a numeral “1” instead of the letter “l” – and buying an EV certificate saying it is the eBay Inc. online payment service.

The certificate issuer would discover the person requesting it doesn’t really work for eBay after obtaining eBay’s contact information through independent means and asking directly, said Paulo Kaiser, vice president of operations for certificate vendor Comodo.

In the early days of e-commerce, merchants simply needed a standard security certificate for browsers to display a closed-padlock icon. The makers of the Netscape browser, now owned by Time Warner Inc.’s AOL, developed the Secure Sockets Layer technology in the mid-’90s, and many online shoppers over time knew to look for it.

Companies known as certification authorities used to always perform a series of checks to make sure sites were really what they said they were.

But newer authorities have tried to cut costs and corners by checking only that the site owns the domain name – not the business said to run on that domain, security experts say. Scam artists, needing only a credit card and a domain name, have exploited the loophole to obtain the certificates necessary to appear legitimate.

Enter the Certification Authority/Browser Forum, a group of certificate issuers and browser manufacturers that want to restore trust in the certificates.

Since its formation nearly two years ago, the forum has been hashing out standards that merchants and banks must meet to obtain EV certificates.

Those that fail could get only the regular certificates, for which the IE browser’s address bar would remain white – just like most other sites, good or bad. Over time, Microsoft and others hope Internet users would know to look for a green bar, just like the padlock.

But the forum has figured out how to validate only larger companies, the ones incorporated by a government agency and thus listed in its databases. General partnerships, unincorporated associations, sole proprietorships and individuals are excluded.

Race, the Texas businesswoman, falls in between. Although her MadLeap.com was registered as a limited liability company in Delaware, it’s so new that it might not appear in enough databases, making her business difficult to verify, according to officials at Comodo.

Smaller and newer companies could lose business if consumers leave for larger, established merchants with green bars.

“It is the small merchants who really need the ability to say, ‘I am trusted. Come and do business with me,’” said Melih Abdulhayoglu, chief executive of Comodo. “The big guys who have the brands already have established trust because of brand awareness.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Kroger said theft a reason for Everett Fred Meyer closure. Numbers say differently.

Statistics from Everett Police Department show shoplifting cut in half from 2023 to 2024.

Funko headquarters in downtown Everett. (Sue Misao / Herald file)
FUNKO taps Netflix executive to lead company

FUNKO’s new CEO comes from Netflix

Inside El Sid, where the cocktail bar will also serve as a coffee house during the day on Tuesday, Aug. 12, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
New upscale bar El Sid opens in APEX complex

Upscale bar is latest venue to open in APEX Everett.

Mattie Hanley, wife of DARPA director Stephen Winchell, smashes a bottle to christen the USX-1 Defiant, first-of-its kind autonomous naval ship, at Everett Ship Repair on Monday, Aug. 11, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
No crew required: Christening held for autonomous ship prototype in Everett

Built in Whidbey Island, the USX-1 Defiant is part of a larger goal to bring unmanned surface vessels to the US Navy.

Cassie Smith, inventory manager, stocks shelves with vinyl figures in 2020 at the Funko store on Wetmore Avenue in Everett. (Andy Bronson / The Herald)
Everett-based Funko reports $41M loss in the 2nd quarter

The pop culture collectables company reported the news during an earnings call on Thursday.

A Boeing 737 Max 10 prepares to take off in Seattle on June 18, 2021. MUST CREDIT: Bloomberg photo by Chona Kasinger.
When Boeing expects to start production of 737 MAX 10 plane in Everett

Boeing CEO says latest timeline depends on expected FAA certification of the plane in 2026.

Kongsberg Director of Government Relations Jake Tobin talks to Rep. Rick Larsen about the HUGIN Edge on Thursday, July 31, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Norwegian underwater vehicle company expands to Lynnwood

Kongsberg Discovery will start manufacturing autonomous underwater vehicles in 2026 out of its U.S. headquarters in Lynnwood.

Logo for news use featuring the municipality of Snohomish in Snohomish County, Washington. 220118
Garbage strike over for now in Lynnwood, Edmonds and Snohomish

Union leaders say strike could return if “fair” negotiations do not happen.

Richard Wong, center, the 777-X wing engineering senior manager, cheers as the first hole is drilled in the 777-8 Freighter wing spar on Monday, July 21, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Boeing starts production of first 777X Freighter

The drilling of a hole in Everett starts a new chapter at Boeing.

Isaac Peterson, owner of the Reptile Zoo, outside of his business on Tuesday, Aug. 19, 2025 in Monroe, Washington. (Olivia Vanni / The Herald)
The Reptile Zoo, Monroe’s roadside zoo, slated to close

The Reptile Zoo has been a unique Snohomish County tourist attraction for nearly 30 years.

Downtown Edmonds is a dining destination, boasting fresh seafood, Caribbean-inspired sandwiches, artisan bread and more. (Taylor Goebel / The Herald)
Edmonds commission studying parking fees and business tax proposals

Both ideas are under consideration as possible revenue solutions to address a $13M budget shortfall.

Ben Paul walks through QFC with Nala on Saturday, July 14, 2018 in Everett, Wa. (Olivia Vanni / The Herald)
QFC to close Mill Creek location, part a plan to close similar stores across the nation

A state layoff and closure notice says 76 employees will lose their jobs as a result of the closure.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.