Certificate authorities are supposed to vet the domains that get certificates and hence bear that supposedly trusty padlock. But it looks like the vetting is actually a bit lackadaisical, according to internet services provider Netcraft. In just one month, CAs have issued hundreds of certificates for deceptive domain names targeting brands including Paypal, Apple, Bank of America, and UK financial institutions Halifax and NatWest. CAs offerings including free trial certificates with short expiration times are appealing to phishers.”]

