7 ms·
Because people seem to be missing it, here's a quote from the project website: "sslip.io's primary purpose is to assist developers who need to test against val
by EngineerBetter 11y ago
Because people seem to be missing it, here's a quote from the project website:
"sslip.io's primary purpose is to assist developers who need to test against valid SSL certs, not to safeguard content."
- viraptor 11y agoI don't think they're missing it. It's a bad idea and you can have your own valid certificate for free from many companies. Or for test, you can create your own cert in 2 lines of bash. (and add the ca to trusted store, so it's just as valid as this one) For testing purposes you can also generate your certs valid only for a few hours/days, so you can be sure they never get used in production by accident. And with proper SAN entries.
- radiac 11y agoExactly - there's no need for a service like this when you can have self-signed certificates. Create a CA cert to distribute across your team, then use it to sign host, wildcard and SAN certs as needed. If you need to share your site with people who don't have your CA cert, it's time to get a real one. In case it helps anyone, I wrote an openssl wrapper with a simple syntax to manage self-signed CAs: https://github.com/radiac/caman https://github.com/radiac/caman
- brohee 11y agoThat statement will totally prevent bad guys from using the trusted cert to scam...
- Dylan16807 11y agoI don't see how 'bad guys' are helped by having a working cert for 1-2-3-4.weirdacronym.io Would you care to elaborate? They could get a free cert other places, and even look like a real domain.
- brohee 11y agoThey would have gotten a valid certificate that couldn't be tied in anyway to their identity. Coupled with e.g. a XSS vuln on a secured website, you could serve a nasty browser exploiting payload from a secure site, without any warning such as "this page is trying to load stuff from an unsecure site". This in only one scenario, there are others. This really was pretty bad.
- Dylan16807 11y agoFree certs are tied to your identity? More than having the IP? SSL is not the place to enforce content restrictions.
- Karunamon 11y agoNot even the paid certs that most people buy are tied to identity. Those only validate control of the domain (usually by having you whack some garbage into a DNS TXT record). Yet another reason why the SSL PKI is a scam and a racket.
- brohee 11y agoBy proving control of the domain, there is a link between the certificate and the person asking for it thru the registrar. And thru the payment information to the registrar, you can usually get to someone. It's a tenuous link, but a lot better than no link at all. At times enough for law enforcement to follow the tracks. (edit since we reached maximum comment depth) Control of an IP address doesn't mean trackable ownership of it, you could use any machine your just compromised and instantly have a valid certificate for it. Delays in certificate issue add a thin layer of security, even if you gained unlegitimate control of a domain, the interval before asking and getting a certificate offers an opportunity for the intrusion to be detected and remediated. Instant valid certificate for any IP address you happen to compromise is really quite bad.
- Dylan16807 11y ago
- hsivonen 11y agoOnce you look at it from the perspective of the crypto protecting the user instead of the content, it should be obvious why publishing the private key is not OK.