3 ms·
Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com
by varenc 2mo ago
Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com
- lee_ars 2mo agoYou'd think, but nope, it def doesn't — the site's TLS cert is issued by Google Trust Services, which issues domain-validated certs via ACME, so no, the only thing the site owner had to do to get that certificate is demonstrate ownership of the `cloudflare.pay` domain. GTS is also one of the default CAs that Cloudflare's universal SSL uses, so that's also exactly what would show up for any Cloudflare-proxied site with TLS enabled. The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either. The domain's whois is also devoid of identifying details: https://rdap.nominet.uk/pay/domain/cloudflare.pay https://rdap.nominet.uk/pay/domain/cloudflare.pay Registered through 101domain, with nothing except a registrar abuse contact. I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck. edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.
- varenc 2mo agohah thanks for the deep dive on this. I wanted to investigate myself but figured someone on HN would be faster at it. Makes sense it's not helpful, alas.
- frollogaston 2mo agoHow would that association be shown to the user? Currently we're trained to check that the domain name is the same.