7 ms·
Incredible :) On a side note: I never realized that all certs issued are publicly listed. This is a pretty big security implication for anyone issuing certs fo
by below43 4y ago
Incredible :)
On a side note: I never realized that all certs issued are publicly listed. This is a pretty big security implication for anyone issuing certs for services that are not intended for public consumption.
- ehPReth 4y agoIf your service's/computer's security requires a hostname to be secret you have big big problems and they aren't the certificate transparency log.
- jlokier 4y agoHostnames are still private information, for example they could be embarrassing and personal. In general private information should not be made public without knowledge and consent. They also sometimes reveal internal topology, which while it shouldn't be central to security, is often best kept private just as another layer of defence in depth. The GP is not the first person to discover long after the fact that their internal hostnames have been added to the public log, which might have prompted them to use different hostnames. It should be made clear that hostnames are posted publically. I just checked and it's not mentioned in the Certbot man page or online documentation, nor mentioned in the log output.
- tinus_hn 4y agoCertificate transparency demands the same from all authorities. This is not limited to LetsEncrypt.
- jlokier 4y agoI'm aware, because I read about these things in some depth, but not everyone knows about certificate transparency. Why would they if it isn't highlighted? As I said, it's not mentioned in the Certbot documentation. There's no warning. It's not obvious at all.
- tinus_hn 4y agoIt’s in the LetsEncrypt privacy policy Certbot has you agree to: > We need to be able to demonstrate to the public, including those who rely on the trustworthiness of our certificates, that our services perform as expected. As a result, we may be unable to delete information, including IP addresses. This information may be made public in a number of ways, including via public API, public repositories, and/or public discussions.
- AndyMcConachie 4y agoI've never really bought into the argument that DNS zone walking represented any kind of security problem. So what if people know the names I'm using for my computers? For all the times I've heard people complain about it I have never encountered an actual security situation, or case study, that showed they were an issue. Does anyone know of a security incident that occurred because of publicly releasing internal DNS names? I would like to hear about it.
- ericpauley 4y agoHere’s one example, where an adversary can use certificate transparency to discover and squat on domains pointed at clouds: https://www.ndss-symposium.org/wp-content/uploads/2018/02/ndss2018_06A-4_Borgolte_paper.pdf https://www.ndss-symposium.org/wp-content/uploads/2018/02/nd...
- justsomehnguy 4y ago> all certs issued are publicly listed By public issuers. Non-public issuers don't list their certs... until someone stumbles on it and record it, eg: https://search.censys.io/certificates?q=%28tags.raw%3A+%22untrusted%22%29+AND+tags.raw%3A+%22unexpired%22& https://search.censys.io/certificates?q=%28tags.raw%3A+%22un...
- agartner 4y agoUsing a wildcard domain (*.agartner.com) helps mask the actual subdomain fyi
- jaxrtech 4y agoSo is this the use-case for going through the trouble of having a private Root CA that all your machines trust?