3 ms·
The account is the same as you create in any acme client. I don't see potential for a reverse lookup.
by gsich 8mo ago
The account is the same as you create in any acme client. I don't see potential for a reverse lookup.
- Ayesh 8mo agoI think the previous post is talking about a search that will find the sibling domain names that have obtained certificates with the same account ID. That is a strong indication that those domains are in the same certificate renewal pipeline, most likely on the same physical/virtual server.
- mschuster91 8mo agoRun ACME inside a Docker container, one instance (and credentials) for each domain name. Doesn't consume much resources. The real problem is IP addresses anyway, CT logs "thankfully" feed information to every bad actor in real time, which makes data mining trivially easy.
- cortesoft 8mo agoyou dont even need a docker container to do that.
- mschuster91 8mo agoAgreed, that's just a personal preference thing of me. Harder to mess up and easier to route.
- TrueDuality 8mo agoThis is publicly publishing the account ID. There is an optional extension in RFC8659 that extends it but it isn't required by any implementer. This puts that ID into a public well known location that is easy to scrape and will be (this is exactly the kind of opsec info project like Maltego love to go lookup and pull in).