3 ms·
How does issuing certificates for test1.com, test2.com, test3.com etc. "threaten the integrity of the encrypted Web"?
by paralelogram 10y ago
How does issuing certificates for test1.com, test2.com, test3.com etc. "threaten the integrity of the encrypted Web"?
- hannob 10y agoThese domains belong to someone. Someone who likely hasn't agreed. It's deeply troubling when a CA says: "We'll just issue some test certs for domains that sound like we could use them for testing - no matter whom they belong to and if they agree to that." It's quite simple: Don't issue certs unless the owner of that domain has asked you for it. But if you look closer at Andrew's mail: There were a bunch of other certs for all kinds of domains.
- cube00 10y agoEspecially when we have TLDs for this purpose (.test and .invalid), it's just plain sloppy.
- JumpCrisscross 10y ago> * it's just plain sloppy* Sloppy is an oopsy. This is negligence.
- agwa 10y agoCAs would not be allowed to use those TLDs under the current rules. They have two options for testing: 1. Use domains they own. 2. Use a testing environment that doesn't issue publicly-trusted certificates.
- tialaramex 10y agoIt's not about these particular certificates, it's about the fact that Symantec issued obviously bogus certificates at all, and then that they either didn't catch it or they caught it and decided to try not to tell us about it. Even at best this is further evidence of incompetence, and incompetence certainly does threaten the integrity of the encrypted Web. Ask yourself, if Symantec's "security" systems can issue for example.com without getting consent from the owner of example.com and Symantec don't notice, why not for your domain, or mine, or a big bank?
- deleted 10y ago[deleted]
- borplk 10y agoHow does it not threaten the integrity of the encrypted Web?