{"id":6363,"date":"2023-03-23T12:23:23","date_gmt":"2023-03-23T15:23:23","guid":{"rendered":"https:\/\/www.certisur.com\/?page_id=6363"},"modified":"2023-05-02T18:25:11","modified_gmt":"2023-05-02T21:25:11","slug":"why-is-it-not-safe-to-trust-browser-locks","status":"publish","type":"page","link":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/","title":{"rendered":"Why is it not safe to trust browser locks"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"6363\" class=\"elementor elementor-6363 elementor-6362\" data-elementor-post-type=\"page\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-253db3f cs-elementor-noticia-header elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"253db3f\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-753a928\" data-id=\"753a928\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-49d3e03 elementor-widget elementor-widget-heading\" data-id=\"49d3e03\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Why is it not safe to trust browser locks<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8b1dcd6 elementor-widget elementor-widget-text-editor\" data-id=\"8b1dcd6\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The popular browser locks are now going out of style, as most hackers use them as well.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-59077b3 cs-elementor-noticia-header-date elementor-widget elementor-widget-text-editor\" data-id=\"59077b3\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t23 March, 2023\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e40cb66 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"e40cb66\" data-element_type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4861014c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4861014c\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2f07e9d9\" data-id=\"2f07e9d9\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2fdc8359 elementor-widget elementor-widget-text-editor\" data-id=\"2fdc8359\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>For years, Google, Apple, Firefox and Microsoft relentlessly pointed out that, to avoid dealing with fraudulent sites, one had to make sure that the &#8220;lock&#8221; on your browser was closed, green, or that it indicated that a site was &#8220;safe.&#8221; Now, cybersecurity companies are emphasizing that those locks are not enough to provide reliability.<\/p>\n<p>\u201cYou have to look beyond the lock,\u201d said Dean Coclin, DigiCert&#8217;s Senior Director of Business Development. &#8220;They just can&#8217;t be trusted anymore.&#8221;<\/p>\n<p>This is because, years after all the major browsers have added visual safety signs to their address bars, today they are removing them, leaving only the padlock that is not enough to know if a site is really safe.<\/p>\n<p>The Anti-Phishing Working Group (APWG) published a study that tracked a large increase in phishing attacks in the second quarter of 2020. The increase involves fraudulent sites using the Transport Layer Security or TLS cryptographic protocol, more commonly known for its inherited name Secure Sockets Layer, or SSL.<\/p>\n<p>SSL locks indicate that a browser is using a secure and encrypted communication protocol with the server hosting the desired website. The SSL warnings are also supplemented by the additional indication &#8220;HTTPS&#8221; within the address bar of the browser, which means that the browser is transmitting the information in an encrypted manner.<\/p>\n<p>According to the APWG report, 80 percent of phishing sites used SSL certificates in the second quarter. The attacks ranged from phishing lures targeting fake bank transfer sites to social media platforms like Facebook and WhatsApp receiving links to suspicious domains.<\/p>\n<p>The availability of free or very low cost TLS \/ SSL certificates, without validation of the identity of the website owner, has impaired Internet security in recent years. But today the problem has become chronic, Coclin said. &#8220;Since the last great browser added SSL warnings to its address bar, hackers have been forced to use SSL \/ TLS locks as well,&#8221; he said.<\/p>\n<p>Fraudulent domain certificates have mainly been limited to criminals acquiring so-called domain validated certificates acquired for free through services like Let&#8217;s Encrypt.<\/p>\n<p>Domain Validated Certificates are a basic solution to protect communications between a web browser and a server using TLS encryption. Several free services have an automated system that only verifies that an applicant has control over a domain before issuing a free certificate. It is a system ready for abuse by issuing the certificates without any other type of control or validation, experts say.<\/p>\n<p>Without a doubt, Extended Validation (EV) and Organizational Validation (OV) certificates are more secure. These top-level certificates used by banks, insurers, and e-commerce sites require extensive research from applicants to ensure that the sites are from who they claim to be and are rightfully owned.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-65d3d75f elementor-widget elementor-widget-image\" data-id=\"65d3d75f\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1.png\" title=\"\" alt=\"Phishing\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7383ab70 elementor-widget elementor-widget-text-editor\" data-id=\"7383ab70\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Percentage of phishing attacks hosted on HTTPS<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c3f9c40 elementor-widget elementor-widget-text-editor\" data-id=\"6c3f9c40\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The main concern has been that Extended Validated Domain Certificates offer criminals an easy way to facilitate website spoofing, server spoofing, man-in-the-middle attacks, and a way to infiltrate malware through company firewalls.<\/p>\n<p>Unsuspecting users may think that they are communicating with trusted sites because the identity of the site has been validated by a certification authority, without realizing that they are certificates in whose issuance process only the domain has been validated, without checking whether its owner or manager is a legitimate business or organization.<\/p>\n<p>The remedy for browser companies, Coclin said, has been to implement new safe browsing tools like Google&#8217;s Safe Browsing for Chrome and Microsoft&#8217;s SmartScreen filter, which makes safe browsing easier for Internet Explorer and Edge browsers.<\/p>\n<p>Coclin cautions that these are workarounds and that what really needs to be done is a review of the domain registration system. &#8220;In the first place, I don&#8217;t know why people can register clearly fraudulent domains,&#8221; he said. \u201cThe problem is that nobody wants to own this problem. And until someone does, users have to look a little beyond the lock.&#8221;<\/p>\n<p><strong>It is very important that when browsing a Transactional Web site the data that is in the certificate is verified, to verify who is the owner of the site<\/strong> (as long as it is a Validated Organization or Extended Validation certificate, since the Domain Validated do not have that information). In this way, users can safely check if the site operator is indeed the company with which they intend to operate. To do this, simply click on the padlock in the navigation bar.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>The popular browser locks are now going out of style, as most hackers use them as well. For years, Google, Apple, Firefox and Microsoft relentlessly pointed out that, to avoid dealing with fraudulent sites, one had to make sure that the &#8220;lock&#8221; on your browser was closed, green, or that it indicated that a site [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":4975,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[69],"class_list":["post-6363","page","type-page","status-publish","hentry","category-news"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CertiSur<\/title>\n<meta name=\"description\" content=\"Browser locks are now going out of style, as most hackers use them as well.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why is it not safe to trust browser locks\" \/>\n<meta property=\"og:description\" content=\"Browser locks are now going out of style, as most hackers use them as well.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/\" \/>\n<meta property=\"og:site_name\" content=\"CertiSur\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/CertiSur\" \/>\n<meta property=\"article:modified_time\" content=\"2023-05-02T21:25:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@CertiSur\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/\",\"url\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/\",\"name\":\"Why is it not safe to trust browser locks\",\"isPartOf\":{\"@id\":\"https:\/\/www.certisur.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png\",\"datePublished\":\"2023-03-23T15:23:23+00:00\",\"dateModified\":\"2023-05-02T21:25:11+00:00\",\"description\":\"Browser locks are now going out of style, as most hackers use them as well.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#primaryimage\",\"url\":\"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png\",\"contentUrl\":\"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"News\",\"item\":\"https:\/\/www.certisur.com\/en\/news\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why is it not safe to trust browser locks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.certisur.com\/en\/#website\",\"url\":\"https:\/\/www.certisur.com\/en\/\",\"name\":\"CertiSur\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.certisur.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.certisur.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.certisur.com\/en\/#organization\",\"name\":\"CertiSur\",\"url\":\"https:\/\/www.certisur.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.certisur.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.certisur.com\/wp-content\/uploads\/Logo-CertiSur-Signo-de-Confianza-300dpi-copy.png\",\"contentUrl\":\"https:\/\/www.certisur.com\/wp-content\/uploads\/Logo-CertiSur-Signo-de-Confianza-300dpi-copy.png\",\"width\":3075,\"height\":2483,\"caption\":\"CertiSur\"},\"image\":{\"@id\":\"https:\/\/www.certisur.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/CertiSur\",\"https:\/\/x.com\/CertiSur\",\"https:\/\/www.youtube.com\/c\/TecnologaCertiSur\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CertiSur","description":"Browser locks are now going out of style, as most hackers use them as well.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/","og_locale":"en_US","og_type":"article","og_title":"Why is it not safe to trust browser locks","og_description":"Browser locks are now going out of style, as most hackers use them as well.","og_url":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/","og_site_name":"CertiSur","article_publisher":"https:\/\/www.facebook.com\/CertiSur","article_modified_time":"2023-05-02T21:25:11+00:00","og_image":[{"url":"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_site":"@CertiSur","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/","url":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/","name":"Why is it not safe to trust browser locks","isPartOf":{"@id":"https:\/\/www.certisur.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#primaryimage"},"image":{"@id":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png","datePublished":"2023-03-23T15:23:23+00:00","dateModified":"2023-05-02T21:25:11+00:00","description":"Browser locks are now going out of style, as most hackers use them as well.","breadcrumb":{"@id":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#primaryimage","url":"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png","contentUrl":"https:\/\/www.certisur.com\/wp-content\/uploads\/StatCounter-browser-AR-monthly-201902-202002-bar-1-1024x576.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.certisur.com\/en\/news\/why-is-it-not-safe-to-trust-browser-locks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"News","item":"https:\/\/www.certisur.com\/en\/news\/"},{"@type":"ListItem","position":2,"name":"Why is it not safe to trust browser locks"}]},{"@type":"WebSite","@id":"https:\/\/www.certisur.com\/en\/#website","url":"https:\/\/www.certisur.com\/en\/","name":"CertiSur","description":"","publisher":{"@id":"https:\/\/www.certisur.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.certisur.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.certisur.com\/en\/#organization","name":"CertiSur","url":"https:\/\/www.certisur.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.certisur.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.certisur.com\/wp-content\/uploads\/Logo-CertiSur-Signo-de-Confianza-300dpi-copy.png","contentUrl":"https:\/\/www.certisur.com\/wp-content\/uploads\/Logo-CertiSur-Signo-de-Confianza-300dpi-copy.png","width":3075,"height":2483,"caption":"CertiSur"},"image":{"@id":"https:\/\/www.certisur.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/CertiSur","https:\/\/x.com\/CertiSur","https:\/\/www.youtube.com\/c\/TecnologaCertiSur"]}]}},"_links":{"self":[{"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/pages\/6363","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/comments?post=6363"}],"version-history":[{"count":0,"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/pages\/6363\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/pages\/4975"}],"wp:attachment":[{"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/media?parent=6363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.certisur.com\/en\/wp-json\/wp\/v2\/categories?post=6363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}