Extended Validation SSL Certificates 2 Years Old
27th February, 2009
Two years after their first appearance in the Netcraft SSL Survey, there are now more than 11 thousand Extended Validation (EV) SSL certificates in use on the Web. Despite enjoying two years of continued growth, EV SSL certificates still only make up around 1% of all SSL certificates in use on the Internet.

Nearly all modern browsers now support EV SSL certificates by colouring all or part of the address bar in green.
The proportion of EV SSL certificates rises considerably amongst the world's busiest websites, as shown by Netcraft's top 1 million sites dataset. In general, it seems, the more traffic an SSL site has, the more likely it is to use an EV certificate, and in particular, more than a quarter of the SSL certificates within the top 1,000 sites have extended validation.
Population | SSL Certificates | EV SSL Certificates | EV SSL Share |
---|---|---|---|
All Sites | 1,028,868 | 11,300 | 1.1% |
Top 1,000,000 | 45,851 | 2,662 | 5.8% |
Top 100,000 | 7,012 | 710 | 10.1% |
Top 10,000 | 712 | 115 | 16.2% |
Top 1,000 | 60 | 17 | 28.3% |
Posted by Paul Mutton in Security
Related News
24 of the 100 top HTTPS sites now safe from TLS renegotiation attacks
25 Nov 2009
Security
24 of the 100 most popular HTTPS websites appear to be safe from the recently documented TLS renegotiation flaws. Meanwhile, the other 76 sites are still vulnerable to renegotiation attacks, which allow a man-in-the-middle attacker to inject data into...
View full post
HMRC phishing site hosted on gov.uk domain
1 Sep 2009
Security
An ongoing phishing attack against UK taxpayers is being given additional credibility by using a gov.uk domain. Sefton Council is hosting the phishing content on its Novel GroupWise 7.0 site at web11.sefton.gov.uk. The phish follows one of the typical...
View full post
Apache.org Compromised
28 Aug 2009
Security
Apache.org has been offline for 3 hours this morning, after one of their servers was compromised. Their sites were displaying the message:
The message goes on to say that the compromise is "not due to any software exploits in Apache itself", but was...
View full post