# SSL used by scammers

**URL:** <https://community.letsencrypt.org/t/ssl-used-by-scammers/55133>\
**Category:** Help\
**Created:** [March 8, 2018, 6:23pm UTC](https://community.letsencrypt.org/t/ssl-used-by-scammers/55133 "2018-03-08T18:23:16Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [March 8, 2018, 7:28pm UTC](https://community.letsencrypt.org/t/ssl-used-by-scammers/55133/5 "2018-03-08T19:28:57Z")

</div>

> [@kenorb](#):
>
> How one can identify the real owner based on the certificate?

Depends on the certificate. There are three different types of certificates:

- Domain validated certificates: [Domain-validated certificate - Wikipedia](https://en.wikipedia.org/wiki/Domain-validated_certificate)
- Organisation validated certificates: [Public key certificate - Wikipedia](https://en.wikipedia.org/wiki/Public_key_certificate#Organization_validation)
- Extended validation certificates: [Extended Validation Certificate - Wikipedia](https://en.wikipedia.org/wiki/Extended_Validation_Certificate)

Only with the extended certificate you can know for a certain certainty the "real owner", i.e., the legal representative of a domain. Which propably could be some sort of shell company..

Domain validation, which most certificates are, are just that: with aid of the public key infrastructure, you can be certain it's actually the server responsible for the _hostname_ you're connecting to. And nothing more than that. **It does NOT validate the CONTENTS of the site! Certificates were NEVER meant for that! It's just verifying you're actually connecting to the scam-site. It's up to THE USER to check for scams or not.**

It's beyond me why people think the "green lock" says anything about the contents of a website. It only says the connection to the scam or phishing site is secure! Yay! Your credit card info isn't interceptable by a man in the middle attacker when you're st\*p\*d enough to fall for a scam-site with a green lock 😛

---

_[View the full topic](https://community.letsencrypt.org/t/ssl-used-by-scammers/55133)._
