5 ms·
They didn't impersonate letsencrypt so that doesn't apply.
by Hondor 10y ago
They didn't impersonate letsencrypt so that doesn't apply.
- arthur2e5 10y agoIt's true that they didn't impersonate letsencrypt, but they did: 1. Assign DNS records to these two domains and remove them after someone exposed these domains. https://groups.google.com/d/msg/mozilla.dev.security.policy/E13eT13wMBQ/jNTh-5K1CQAJ; https://groups.google.com/d/msg/mozilla.dev.security.policy/... https://archive.fo/MQwMK; https://archive.fo/MQwMK; https://archive.fo/0HQZ7 https://archive.fo/0HQZ7 2. Send marketing e-mails that exaggerate threats of using a "foreign CA", such as Let's Encrypt: https://groups.google.com/d/msg/mozilla.dev.security.policy/E13eT13wMBQ/Cky6aXbZCQAJ https://groups.google.com/d/msg/mozilla.dev.security.policy/... (Well, "Percy" has always been bringing it up.) While (2) has been something too old to keep bringing up, (1) certainly undermines some of Richard Wang's claim.