7 ms·
It used to be that to get a SSL certificate you had to provide a Dun & Bradstreet ID, and go through a minor audit. Was the Internet safer then? Well I certainl
by miah_ 3y ago
It used to be that to get a SSL certificate you had to provide a Dun & Bradstreet ID, and go through a minor audit. Was the Internet safer then? Well I certainly wasn't being phished in the 90's because it wasn't really a thing yet. I enjoy what Letsencrypt brings us so I don't want to go back to that, but I do believe the registrars are certainly partially to blame here, look at Google and .zip, how many valid domains are registered with that TLD, and how many are malicious? We can make better decisions, it just requires not being so damned greedy.
- burnte 3y agoOnly some vendors did that, most didn't. And that was back in the days when we though SSL would be useful for ID verification, which it never was meant to be used for.
- kube-system 3y agoThose barriers to entry meant basically nobody hosted malicious sites with an SSL cert back then. "Look for the lock" was a valid security recommendation in those days.
- indymike 3y agoActually, we'd just see the web part of an attack on a hacked webserver, often with an wildcard EV cert. something.majorcorp.com/some/backwater/director/index.htm. The funny part is the phish would look like something at UPS and be hosted on some airline site, so the advice to check the link was the best defense.
- fullspectrumdev 3y agoI still see this pretty much daily. Usually you find the mailer script (for spamming), a web shell, and a few different phish kits all under some directory. Also usually the captured credentials, etc. Sloppy work from the crooks, but it works.
- nulbyte 3y ago> It used to be that to get a SSL certificate you had to provide a Dun & Bradstreet ID, and go through a minor audit. What kind of audit? And was it conducted by DNB? If so, some audit it must have been. I can't speak to the time before, but these days, DNB is a scam in and of itself. Just last year, the FTC finalized its order against them for deceptively selling a junk business credit monitoring service and failing to correct errors on business credit reports--even today, they'll tell you they don't know who provided the data that they themselves collected in the first place.
- miah_ 3y agoIt wasn't a "audit" in the sense it is today, just a 'is this a real business?' 'not impersonating another business/person' kind of audit. Wasn't too difficult to pass if you had a business set up. It was conducted by the company issuing the SSL certificate. Getting your initial cert could take anywhere from 24hours to a few days. Once you were set up renewals weren't a big deal. Nowadays its all automated of course, anybody can get a cert easily and thats great!