On Thu, Aug 15, 2019 at 4:27 AM Peter Gutmann <pgut001 at cs.auckland.ac.nz>

In any case it'll be interesting to see what the next
> deckchair-rearrangement
> in browser PKI will be.  Whatever it is, I'd like to take this opportunity
> to
> predict in advance that it'll have no effect.

The next major advance in browser PKI is already here in Firefox. It is DNS
over HTTPS which needs to be manually turned on (separately, the default
resolver, provided by Cloudflare, also supports DNSSEC). At some point this
will become enabled by default (along with https connections) and then EV
will be irrelevant, or perhaps exist as a mirror image version that serves
to indicate when the connection you have is NOT some combination of:

- Connection being https encrypted
- DNS lookup being https encrypted
- server certificate being validated



