3 ms·
They're not verifying your identity, just that you control the hardware running the domain that you want to generate a certificate for.
by codebeaker 9y ago
They're not verifying your identity, just that you control the hardware running the domain that you want to generate a certificate for.
- peterwwillis 9y agoCorrection: that you can control the IP space advertised to Let's Encrypt. A BGP exploit would result in getting valid certs for someone else's domain/host. It's almost trivial to exploit BGP, which is why PKI is so important... so it should actually be incredibly difficult to get a cert.
- discreditable 9y agoIf someone is hijacking BGP to MITM the world, how are the old methods any better?
- snuxoll 9y agoIf you could hijack BGP you could just as easily inject routes to intercept DNS requests as well.