5 ms·
> Also, Let's Encrypt security is a joke - they issued fake certificate without serious checking. Using unencrypted HTTP for confirmation is a vulnerability Th
by ItsABytecode 3y ago
> Also, Let's Encrypt security is a joke - they issued fake certificate without serious checking. Using unencrypted HTTP for confirmation is a vulnerability
They can’t use HTTPS if you don’t have a certificate yet
- codedokode 3y agoThis doesn't mean you should use unsecure methods instead and issue certificates to anyone capable to do MitM.
- blueflow 3y agoHow could Letsencrypt even verify a server setup if not via DNS/HTTP? Also, verify against what? The servers are basically random strangers without identity when they first talk to LE.
- codedokode 3y agoIn this case there has been a valid certificate for the site; this alone should raise suspicion. Also, if they cannot do secure validation then maybe they should stop issuing certificates for sites that already have a proper certificate.
- blueflow 3y agoThis happens all the time when a server is rebuilt from scratch - same cert using a different keypair.
- codedokode 3y agoSo should we conclude that SSL cert infrastructure is completely compromised and now any country can issue fake certificates?
- blueflow 3y agoNo, there is no reason to jump to such extremes.
- codedokode 3y agoThere are approximately 10 Tier-1 ISPs through which majority of Internet traffic passes, and unless I misunderstood something, they can issue valid certificates for almost any domain. To me it looks like "completely compromised".
- blueflow 3y agoEvery CA can issue valid certificates for every domain? And it always has been that way.
- codedokode 3y agoCA has a risk to get their root cert removed from browsers; ISP doesn't risk anything especially when asked by the govt.
- blueflow 3y agoThey risk having their peerings cancelled. Also it might be a crime in some countries.
- preisschild 3y agoOver the DNS challenge, of course.
- sigio 3y agoThis is exactly the same as all other CA's do this.... for DV-certificates you basically place a key/special file on the webserver, or receive a verficiation code via (plaintext) email. For EV certs there might be more validation, but users will never see the difference between EV and DV certificates.
- codedokode 3y agoSo SSL certificates are completely unreliable; we should only wait until Russian or Chinese comrades find a good use for this attack (e.g. temporary redirecting Western traffic using BGP to validate a Let's Encrypt's cert for Western site).
- bananapub 3y agoyes? this is a well-known problem, which is why CAA-ACME etc and certificate transparency logs exist.