Hacker News new | past | comments | ask | show | jobs | submit login

You don’t care if the banking website you’re using is actually owned by your bank?



For physical banks, every piece of stationary from my bank states their domain name so once I have a DV verified showing I'm actually connected to that domain I can trust it.

For online banks, I only got to them online by which automatically means I have their correct domain name.

The question of how I get the online bank's domain name to begin with does not really come in to this conversation, can be an ad, a friend etc.


Most people don’t visit URLs by typing them into their browser. Links, messaging apps, email, native apps etc. account for more than manually typed links do.


The EV UI was sunset in all browsers because as it turns out, ensuring that your address bar says 'wellsfargo.com' and that you didn't get MITM'd is plenty good enough due to the other protections.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: