Comment by hobarrera

11 years ago

> 200 bucks for us to say he's cool

There are trusted free certificates as well, like the ones from StartSSL.

> if a bank pays 10,000 bucks for a really cool verification, they get a giant green pulsating URL badge

Yeah, $10 000 and legal documentation proving that they are exactly the same legal entity as the one stated on the certificated. All verified by a provider that's been deemed trustworthy by your browser's developers.

Finally, if a certificate is self-signed, it generally should be a large warning to most users: the certificate was made by an unknown entity, and anybody may be intercepting the comunication. Power-users understand when self-signed CAs are used, but they don't get scared of red warnings either, so that's not an issue.