4 ms·
The most egregious certs issued were for *.*.com and *.*.org Why is that even possible? Does it ever make sense for that to exist? If the browsers currently ac
by jackowayed 15y ago
The most egregious certs issued were for *.*.com and *.*.org
Why is that even possible? Does it ever make sense for that to exist? If the browsers currently accept that, I wouldn't be surprised if they stop accepting that since it almost certainly means someone got ahold of certs they shouldn't have.
- rhizome 15y agoHN eats asterisks, so for everybody else in tl;dr-land: "x.x.com" and "x.x.org". Diginotar is looking worse and worse with every revelation, which is probably why they're attempting the silent treatment. This article says "their audit trail is incomplete." Frankly, I think this should be approaching criminality, though I don't think the law has caught up to that. It's an egregious shitting-on-the-internet by Diginotar, though.
- jackowayed 15y agoThanks, did my best to fix. The spaces are suboptimal, but a least the *'s are there.
- sp332 15y agoIf you put two spaces at the beginning of the line, HN will ignore *asterisks*, switch to monospace, and won't wrap.
- 0x0 15y agoYeah, I just asked about that in another thread (http://news.ycombinator.com/item?id=2959789 http://news.ycombinator.com/item?id=2959789) and pondered the use of the public suffix list for limiting wildcards.
- Duff 15y agoMany proxy servers within companies use such certificates to scan incoming traffic for malware/policy violations.
- tptacek 15y agoIt's just as easy for a proxy server to cut per-site certificates on the fly.
- tptacek 15y agoThere is no reason that should have to be possible; it is straightforward for a browser to reject any "wildcard" certificate, and even easier to reject a cert that wants to claim all of ".com". Now, when you think about that, remember: the DNSSEC trust model starts with an entity that can sign anything under .COM. You can't not have that entity in DNSSEC. Now you understand one reason I think DNSSEC sucks.
- __david__ 15y agoI don't know, it still seems better to me than our current situation which is 300 attack surfaces that are all effectively *.*
- throwaway32 15y agoits much worse than that, there are an unknown amount of intermediate CAs that also have this abillity. Several CAs sell these certs freely. So not only can one of the 300 CAs get compromised and totally destroy ssl security, so can a large amount of people you have _no information about at all_.
- bdonlan 15y agoIt's also a LOT easier to recover from a key breach - you expire the old *.com certificate, and publish a new one under the root. No problem. The root key, of course, must be VERY carefully guarded - but since updates are infrequent, this can happen on an isolated system with no network connection (or even more paranoid systems, such as secret sharing schemes...)
- tptacek 15y agoYou can recover from a breach like Diginotar's instantly; just remove their cert from your browser. You have no control over .COM's recovery from a breach.
- tptacek 15y agoYou or I can point or click our way through dealing with a breach of a TLS certificate. Tell me what you'd personally do to deal with a rumored breach or misuse of .COM? Remember: under DNSSEC, Libya would have been BIT.LY's CA.