4 ms·
In this case there has been a valid certificate for the site; this alone should raise suspicion. Also, if they cannot do secure validation then maybe they shou
by codedokode 3y ago
In this case there has been a valid certificate for the site; this alone should raise suspicion.
Also, if they cannot do secure validation then maybe they should stop issuing certificates for sites that already have a proper certificate.
- blueflow 3y agoThis happens all the time when a server is rebuilt from scratch - same cert using a different keypair.
- codedokode 3y agoSo should we conclude that SSL cert infrastructure is completely compromised and now any country can issue fake certificates?
- blueflow 3y agoNo, there is no reason to jump to such extremes.
- codedokode 3y agoThere are approximately 10 Tier-1 ISPs through which majority of Internet traffic passes, and unless I misunderstood something, they can issue valid certificates for almost any domain. To me it looks like "completely compromised".
- blueflow 3y agoEvery CA can issue valid certificates for every domain? And it always has been that way.
- codedokode 3y agoCA has a risk to get their root cert removed from browsers; ISP doesn't risk anything especially when asked by the govt.
- blueflow 3y agoThey risk having their peerings cancelled. Also it might be a crime in some countries.