17 ms·
This site uses the 'Globalsign Organization Validation CA - G2' certificate, which I've removed from my trust list. It's is a certificate that can be theoretica
by taway2012 13y ago
This site uses the 'Globalsign Organization Validation CA - G2' certificate, which I've removed from my trust list. It's is a certificate that can be theoretically used to sign any domain (i.e., it's MITM-capable).
I semi-regularly see it on Cloudflare sites because their customers haven't bothered to send their own keys to Cloudflare.
I thought it was ironic than article about SSL security was doing something that is less secure than possible (from the end user's point-of-view).
Just to be clear, yes, I understand that the operator of brainsmith.org isn't gaining any more security by sending CF the private key to their own cert vs. using CF's G2 cert. With the first approach the end user of brainsmith.org has better security since he can view the site without having to trust an MITM-capable certificate.
- geraldcombs 13y agoIn Cloudflare's case "haven't bothered to send their own keys" implies "haven't seen the need to pay Cloudflare $200/month or $3000/month for the ability to upload a certificate+key". AFAICT only the Business and Enterprise plans allow custom certificates.
- harrytuttle 13y agoWhy the fuck would anyone want to use them then? Even the shittiest shared host or VPS offer that for pittance.
- rgbrenner 13y agoIt's a CDN... comparing to a VPS is not even close to being fair. I've never seen a CDN that will let you load an ssl cert for less than a few hundred dollars. SNI isn't supported widely enough yet, so they have to dedicate an IP to you.