2 ms·
The attacker effectively controlled the IP the domain was pointed to. If you have this, getting a cert issued from any CA is trivial - you've proved to them you
by nmjohn 3y ago
The attacker effectively controlled the IP the domain was pointed to. If you have this, getting a cert issued from any CA is trivial - you've proved to them you control the domain in question.
- 3np 3y agoAs mentioned elsewhere in the thread, RFC 8657 can prevent this. https://news.ycombinator.com/item?id=37958831 https://news.ycombinator.com/item?id=37958831