3 ms·
This is how these sort of attacks have always worked. Get something that's just close enough so that it passes the glance attack. If someone doesn't notice anyt
by Sanddancer 10y ago
This is how these sort of attacks have always worked. Get something that's just close enough so that it passes the glance attack. If someone doesn't notice anything in the first few seconds, you've done half your work right there.
- Buge 10y agoWhat is going to happen in a quick glance? Including a CA in a browser is an extremely long and drawn out processing involving third party audits and many other things costing hundreds of thousands of dollars. There is zero chance that no one along that whole process will notice that the TLD is actually .cn .
- inimino 10y agoObviously, but that's not the concern. The concern is that someone would visit letsencrypt.cn and end up getting a certificate from a provider that is not Let's Encrypt without really understanding that. Imagine a busy, non-SSL-expert user who just hears "Let's Encrypt is good, you should use it". Since the domains aren't being used, we can't say what the intention was, but it's being judged as part of a pattern of behavior by Wosign.
- Buge 10y agoOk, but that's not really a security problem. You don't give out your private key when getting a certificate.
- inimino 10y agoActually many customers let the CA generate the private key and copy it onto their servers, but that's not the point. It's a trust problem because of the pattern of this particular CA. Whether you call that a security problem or not is semantics. If not for the existing pattern of behavior, people would be a little more willing to look charitably on this as an honest mistake or trying to help, but given the history the assumption of good faith has been considerably weakened.