4 ms·
> I'm curious, is this apparent issue of outdated cert bundles also a problem outside of the PHP ecosystem? Yes, that is a problem that would exist outside of
by CiPHPerCoder 9y ago
> I'm curious, is this apparent issue of outdated cert bundles also a problem outside of the PHP ecosystem?
Yes, that is a problem that would exist outside of the PHP ecosystem. We provided a solution for it in our tool because we strive to be forward-thinking.
I'm not aware of any systems being breached because of stale cacert.pem files and the employment of rogue CA certificates, but that's probably due to the rarity of attackers having access to a rogue/compromised CA, and that attackers that do are unlikely to get caught very easily.
It may turn out to be the case that this has never happened before and won't happen in the immediate future, but if a bunch of CAs suddenly get hacked and their private keys are leaked on Pastebin, then this would of course change rapidly.
For these scenarios, I can only prescribe something like Expect-CT to force attackers to leave evidence of their attack behind. https://scotthelme.co.uk/a-new-security-header-expect-ct/ https://scotthelme.co.uk/a-new-security-header-expect-ct/