Re: Logotypes in certificates

Dean Povey <povey@dstc.qut.edu.au> Tue, 20 March 2001 01:21 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id UAA28840 for <pkix-archive@odin.ietf.org>; Mon, 19 Mar 2001 20:21:48 -0500 (EST)
Received: from localhost by above.proper.com (8.9.3/8.9.3) with SMTP id RAA23088; Mon, 19 Mar 2001 17:20:54 -0800 (PST)
Received: by mail.imc.org (bulk_mailer v1.12); Mon, 19 Mar 2001 17:20:48 -0800
Received: from thunder.dstc.qut.edu.au (thunder.dstc.qut.edu.au [131.181.71.1]) by above.proper.com (8.9.3/8.9.3) with ESMTP id RAA23058 for <ietf-pkix@imc.org>; Mon, 19 Mar 2001 17:20:46 -0800 (PST)
Received: from dstc.qut.edu.au (garnet.dstc.qut.edu.au [131.181.71.36]) by thunder.dstc.qut.edu.au (8.10.1/8.10.1) with ESMTP id f2K1Kgm20434; Tue, 20 Mar 2001 11:20:42 +1000 (EST)
Message-Id: <200103200120.f2K1Kgm20434@thunder.dstc.qut.edu.au>
X-Mailer: exmh version 2.2 06/23/2000 with nmh-1.0.4
To: Rich Salz <rsalz@zolera.com>
cc: ietf-pkix@imc.org
Subject: Re: Logotypes in certificates
In-Reply-To: Message from Rich Salz <rsalz@zolera.com> of "Mon, 19 Mar 2001 19:59:06 EST." <3AB6AB5A.3934DBA1@zolera.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Tue, 20 Mar 2001 11:20:38 +1000
From: Dean Povey <povey@dstc.qut.edu.au>
Precedence: bulk
List-Archive: http://www.imc.org/ietf-pkix/mail-archive/
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: mailto:ietf-pkix-request@imc.org?body=unsubscribe

>> Adding some sort of visual identifier, such as a company logo to a
>> certificate and displaying this in a prominent place in the browser would
>> go a long way to ameliorating this problem.
>
>And what's to prevent the badguy from just copying the info out of a
>real cert?  Fear of violating the trademark law?
>	/r$

I should have explained.  It only works if the browser does something 
sensible like displays the logo in a prominent place where the user will 
notice and which can't be recreated by just straight HTML.  Kind of like 
the way the lock clicks on to tell you you have a secure connection.  
Presumably the CA will perform some due-dilligence when certifying company 
logos.

Cheers

-- 
Dean Povey,         | e-m: povey@dstc.edu.au | JCSI:  Java Crypto Toolkit 
Research Scientist  | ph:  +61 7 3864 5120   | uPKI:  C PKI toolkit for embedded
Security Unit, DSTC | fax: +61 7 3864 1282   |        systems
Brisbane, Australia | www: security.dstc.com | Oscar: C++ PKI toolkit