4 ms·
Tangentially related: I’ve wondered what would happen if you purchased a domain name that had previously been owned by someone else and they had obtained a TLS
by HellsMaddy 5y ago
Tangentially related: I’ve wondered what would happen if you purchased a domain name that had previously been owned by someone else and they had obtained a TLS certificate from a CA with an expiration date beyond when your ownership began. This seems like a good tool to find such a certificate, but if you found one what would you do? Would the holder of the certificate be able to MITM or otherwise impersonate you? Would there be a way to revoke the certificate (I’m guessing you could contact the CA that issued it?)? Do CAs automatically revoke certificates when domain ownership changes?
- Rygian 5y agoHow would you retrieve the private key for that certificate?
- HellsMaddy 5y agoYou wouldn’t. But the CA that issued the certificate could still revoke it, correct? E.g. https://letsencrypt.org/docs/revoking/#using-a-different-authorized-account https://letsencrypt.org/docs/revoking/#using-a-different-aut...
- remram 5y agoYes, from that same link you can see that whoever controls the domain can revoke those certificates (by asking Let's Encrypt to revoke it). All you need is the certificate itself (which you can get from the transparency logs e.g. crt.sh), not the private key.
- jeff_carr 5y agoIt's unclear. Do you know what CA's you currently trust on your machine? I bet you can't even identify 1 tenth of them. There are so many CA's installed by default that it's truly a massive man-in-the-middle attack whenever you might think you are safe, you are not. I would assume the CCP & the KGB control at least one of the CA's your OS currently trusts. (No doubt the NSA has one too) In debian: dpkg -L ca-certificates
- deleted 5y ago[deleted]
- iancarroll 5y agoThere's been some research on this! https://insecure.design/ https://insecure.design/
- HellsMaddy 5y agoThat’s awesome, thank you for the link!
- egberts1 5y agoOh … wow. How is LetsEncrypt going to handle revocation … in under 24 hours?