6 ms·
This seem legit...
- chmod775 13y agoTo clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
- namuol 13y agoI love how suddenly the NSA is the only entity out there who has an interest in private keys.
- blueblob 13y agoI think it is pretty hard to argue that they are not one of the most aggressive entities doing this.
- nraynaud 13y agoat least we know that's it is the most interested, funded and staffed to do it.
- ZirconCode 13y agoNo, they're just the only ones dumb enough to get caught ;)
- l34ch 13y agoNo they just had a stupid rat.
- makmanalp 13y agoNever attribute to malice that which is adequately explained by stupidity. This just seems like some newbie programmer was like "hey, wouldn't it be cool if"... and built themselves a weekend project that they released on the site. Obviously it's terrible for a site that sells SSL stuff, but concluding that this is the NSA is pretty hugely premature. edit: Duh, didn't pick up on the sarcasm. In my defense, the parent text was way more vague at the time. :)
- floobynewb 13y agoTo be fair, I'm pretty sure he had his tongue firmly in his cheek. But point well made. Whenever this point comes up I think of a scene from 'the cube', is it a massive conspiracy or utter incompetence combined with some kind emergent process?
- 0xdeadbeefbabe 13y agoOr likely the NSA firmly has their tongue in their cheek teasing and scaring us because they can.
- ddoolin 13y agoNobody else got the subtle sarcasm, but I did. No worries, man. But seriously, if it was the NSA, I like how quick everyone is to dismiss the notion!
- ceautery 13y agoThere are thousands of us who see the subtle implications of comments, and roll our collective eyes at the knee-jerk, replies from people who missed it. The proclivity for this type of boring, predictable reply is the main reason I don't post very much. I tend to get the "you are either stupid or a jerk!!" replies myself. (Rest assured, it's the latter, not the former.)
- codfrantic 13y agoI was hoping it was at least javascript...
- tankenmate 13y agoWoah, I couldn't ever envisage ever trusting a "security company" that not only encouraged you to disclose your private key, but also provided a form for doing it over a non encrypted connection! My personal opinion is don't use these guys; this is either a school boy error/complete incompetence or totally dubious.
- jawr 13y agoBrilliant.
- mgbmtl 13y agoWow, at first I seriously thought this site was a fake copy of the official Trustico site (they have trustico.ca, trustico.com, etc)... but the form exists on all their sites: http://www.trustico.ca/ssltools/match/cert-and-key-pem/check-if-certificate-and-key-match.php http://www.trustico.ca/ssltools/match/cert-and-key-pem/check...
- elithrar 13y agoI had these guys @reply me on Twitter when I tweeted about how it's easier to figure out what cipher suite to use compared to figuring out what SSL product I need. They were helpful but thank god I didn't buy a cert from them: this page is a terrible, terrible idea that erodes their trust completely.
- racbart 13y agoThis should be a feature on the NSA website.
- fosap 13y agoBut has a verysign logo. It has be trustworthy.
- jawr 13y agoI contacted their support: Me: I wanted to know more about your certificate key matcher isn't the private key always meant to remain... private? Emanuele: Yes, it should. We offer the tool to help verify the correspondence SSL certificate it is lost. Me: But it would be sent over HTTP and viewable to anyone along the network. Emanuele: The page can also be accessed through HTTPS. Me: I think it should be enforced. Also something like this should be done client side. Perhaps using crypto.js Emanuele: OK, I will pass your comment to our General manager.
- ctz 13y agoSo leaking my private key to somebody is OK if I do so over HTTPS, and even better if I encrypt it with a javascript crypto library beforehand? I don't think you've thought this through.
- redblacktree 13y agoI think he was suggesting that, instead of sending the private key to this web server, the check they're doing could be implemented client-side, thus avoiding the need for the key to transit the wire. I haven't been able to access the site though, so I may be way off in my understanding of what it does.
- jawr 13y agoSending it over HTTPS at least narrows down the recipient to.. who it's intended for. And I wasn't suggesting encrypting and then sending it to them, instead perform the check on the client side in a way that no information is ever sent back to their server; using the browser as a platform to run an "app". I don't condone this at all, but if they're adamant about providing this service they should at least try and make it less damning than it already is.
- ge0rg 13y agoI just tested the form with a key+cert pair I created for this sole purpose. It actually performs as advertised - it checks if key and cert belong together.
- robzyb 13y agoYou have not provided any proof that it actually performs as advertised. Maybe it just says that for any and all inputs??
- ge0rg 13y agoTo clarify the issue: I performed the following steps: 1. created a CA key+cert (selfsigned) 2. created a keypair K 3. signed the public key of K with the CA 4. uploaded the CA-signed cert and the private key of K --> "Your Certificate and Key match" 5. uploaded the CA cert (not the one of K) and the private key of K --> "Certificate an Key do NOT match."
- terhechte 13y agoBITCOIN ADDRESS MATCHER Want to make sure that your bitcoin address works? Just send money to 1JqjU7zBvbhyrDFjtJG6xAwMm5BUVmtpau and if you don't receive an error, you can rest assured that your bitcoin address works!
- chrisbridgett 13y agohttps://blockchain.info/address/1JqjU7zBvbhyrDFjtJG6xAwMm5BUVmtpau https://blockchain.info/address/1JqjU7zBvbhyrDFjtJG6xAwMm5BU... Watching with interest... xD
- deleted 13y ago[deleted]
- terhechte 13y agoEmpty as expected :) Edit: Nevermind, somebody send a cent. Your address works! ;)
- ye 13y agoI'd rather use this 1PtQmxewNJWYeDUieM2cLqU9XcAoBEfWaQ You send the money there, it sends you back the double amount.
- pepijndevos 13y agoDoesn't work for me. Maybe I need to send a bigger amount for it to trigger?
- mycousinvinny 13y agohttp://i.imgur.com/opc22Lf.gif http://i.imgur.com/opc22Lf.gif
- christopherryan 13y agoGOSPEL ARTIST POSES NUDE! Evon Latrail is the author of a children's book "When Mommy Went to Heaven". She wrote/recorded a few songs; "Lord Bless My Enemies. And, even has a song entitled, "Can't You See (Abortion Is Murder). She went Pro-life after having a abortion! Really???? Now here is a photo of her posing in chocolate as a "Swamp Girl". The word Hypocrite is floating around somewhere. This story has made front page news in the local paper. Go to Google or YouTube and search, Evon Latrail.
- scottydelta 13y agohaha, Its hilarious, reminded me of this http://d24w6bsrhbeh9d.cloudfront.net/photo/350850_700b_v1.jpg http://d24w6bsrhbeh9d.cloudfront.net/photo/350850_700b_v1.jp...
- fishbacon 13y agoThis is of course an old joke from bash.[1] [1]http://www.bash.org/?244321 http://www.bash.org/?244321
- scottydelta 13y agoyes it is, actually this one is better ;)
- deleted 13y ago[deleted]
- utopcell 13y agotoo awesome! :)
- deleted 13y ago[deleted]
- a3_nm 13y agoRelated: http://www.inutile.ens.fr/estatis/password-security-checker/ http://www.inutile.ens.fr/estatis/password-security-checker/
- icebraining 13y agoI love the "Test another password?" prompt. I wonder how many people actually use it.
- NotOscarWilde 13y agoc. You agree to pay $ 100,000 for your use of the Estatis Free Password Security Checker if we ever ask for it.
- hellerbarde 13y agoI was assuming you were joking. but no, it's in there, point 6.c) ... Wat? EDIT: I am a dumbass, the terms and conditions are clearly facetious. Read them, they are hilarious in parts.
- chengsun 13y agoIf you repeatedly test another password, the prompt changes. Quite hilarious. Also, the terms and conditions are fake too. "If you read all the legalese up to this point (or just got there by random scrolling), you probably have noticed that this document is complete nonsense. [...] First, chapter 10 of Mary Shelley's /Frankenstein/. Second, a copy of some treaty."
- swoker 13y agoAnyone else who tested it with "correct horse battery staple"? :D
- kirab 13y ago404 submissions (password not found) Damn, this is becoming addictive.
- danso 13y agoAt the very least, I hope a successful submission is rewarded by a redirect to: http://www.youtube.com/watch?v=awK0NrgHUbk http://www.youtube.com/watch?v=awK0NrgHUbk
- icebraining 13y agoApparently the feature is widespread: https://www.sslshopper.com/certificate-key-matcher.html https://www.sslshopper.com/certificate-key-matcher.html http://www.ssltools.com/cert_key_match http://www.ssltools.com/cert_key_match https://certificatesssl.com/ssl-tools/match-ssl-details.html https://certificatesssl.com/ssl-tools/match-ssl-details.html http://www.mobilefish.com/services/privatekey_match_certificate/privatekey_match_certificate.php http://www.mobilefish.com/services/privatekey_match_certific... http://sslchecker.com/matcher http://sslchecker.com/matcher
- mgbmtl 13y agoScary. To be fair, although this kind of tool should not exist at all, the sslshopper tool at least has a warning, enforces https and informs users how to check it properly on the command line. The others, however, do not.
- ctz 13y agoIt would be really cool if they parsed the issuer from the certificate you provided, and informed your CA that your private key was just compromised if the key matched.
- cornet 13y agoSo I tweeted them earlier and just got this response: "Hello, the tool will be removed from all our websites within the next 30 minutes. Thanks." https://twitter.com/MrTrustico/status/395905251313586176 https://twitter.com/MrTrustico/status/395905251313586176
- trustico 13y agoHello, that tool will be removed from all our websites within the next 30 minutes. Trustico Online Limited
- jcromartie 13y agoCongratulations. Your customer base today = (customer base yesterday) - (hacker news readership).
- Kiro 13y agoWhat was it?
- trustico 13y agoHi, The tool was made available for customers to legitimately check if the Private Key matched the SSL Certificate that was being installed - a common question and feature request from our customers. However, upon review of the comments made in the internet community we have made a decision to remove this specific tool and to review all other tools that we make publicly available via our websites. We also saw a heavy attempt to hack/abuse this tool over the past few hours, perhaps to look for exploits, an action I find absurd for those who make out to be security conscious. I welcome any further comments on how we can improve our service and do hope that our actions to remove the tool today were prompt and satisfactory. Zane Lucas General Manager Trustico Online Limited
- jackmaney 13y agoLook, I have absolutely no background in security, but I could tell immediately that this was an absolutely horrible idea. What were you thinking? That's not a loaded question. I literally have no idea what was going through the mind of anyone at your company when it was decided to build this abomination.
- angersock 13y agoThank you for your prompt response.
- pliny 13y agoSince you are a site that sells SSL certificates, it would be appropriate for you to enforce HTTPS when communicating with your website.
- hellerbarde 13y agoAnd it's been taken down. This is still up though and just as bad: http://www.trustico.ch/ssltools/convert/pem-key-to-der/convert-pem-private-key-to-der.php http://www.trustico.ch/ssltools/convert/pem-key-to-der/conve...
- dspillett 13y ago"The page you have tried to access is not responding properly and we can't display it at the moment." - looks like they are embarrassed enough to take it down. Anyone have the original text for me to snigger at? Way-back machine and Google don't seem to have it cached.