4 ms·
No. It's a fully valid ceritifcate issued by DigiCert to CN = *.facebook.com O = "Facebook, Inc." L = Menlo Park ST = CA C = US with a bun
by spindritf 12y ago
No. It's a fully valid ceritifcate issued by DigiCert to
CN = *.facebook.com
O = "Facebook, Inc."
L = Menlo Park
ST = CA
C = US
with a bunch of altnames
DNS Name: *.facebook.com
DNS Name: facebook.com
DNS Name: *.fb.com
DNS Name: *.fbsbx.com
DNS Name: *.fbcdn.net
DNS Name: *.xx.fbcdn.net
DNS Name: *.xy.fbcdn.net
DNS Name: fb.com
DNS Name: facebookcorewwwi.onion
DNS Name: fbcdn23dssr3jqnq.onion
DNS Name: fbsbx2q4mvcl63pw.onion
- spacefight 12y agoThanks - learned something that you can put anything in the alt names list. So digicert is not checking those to be valid domains and controlled by the cert requester?
- iancarroll 12y agoYou can't put anything in the SubjectAltName field, you can put anything that isn't a valid TLD (and not have to validate it).
- im2w1l 12y agoSo Eve could also get a cert for facebookcorewwwi.onion?
- iancarroll 12y agoYes. I submitted a request for one just now, actually. Hopefully the CA doesn't flag it for containing Facebook.
- iancarroll 12y agoJust had it issued. Probably going to write a blog post now.
- AmustheGreat 12y agoDid you get it from DigiCert? Or from another CA?
- iancarroll 12y agoGlobalSign. edit: They've revoked the cert. :(
- mike_hearn 12y agoBut does TBB check for revocations? I bet the answer is no because otherwise it'd be sending the sites you visit to CA's via OCSP and Tor would never want that. So I think you still win.
- e12e 12y agoYou could still get a full revocation list (via Tor or not). In fact using OCSP over Tor should be safe? FB sees some-exit-node, sends you a cert, CA sees some-other-or-same-but-not-provably-you requesting status of FBs cert. Unless FB sent you a specially craftet, session-spesific cert, CA would only see that "someone" checked the status of FBs cert. And with no immediate link between "you" and "someone"? Much as DNS over Tor is safe (but DNS over udp isn't)?
- e12e 12y agoWhat a shame I didn't put a bunch of likely new TLDs into a cert before they became valid TLDs... ;-)
- iancarroll 12y agoDo note CAs have to revoke all certs within 30 days of ICANN signing a contract with a new TLD provider.
- spindritf 12y agoI would assume that DigiCert checked each and every one of those.
- feld 12y agoThey got their money; I doubt they cared.
- AmustheGreat 12y agoNo - each name is checked before issuance. .onion is an interesting one though since there isn't WHOIS info. The only check there is to download Tor and check that FB controls the service.
- feld 12y agoAnd there's been another article now showing that someone else was able to successfully obtain a certificate for that same .onion address.
- wowaname 12y agoOr to give the CA a copy of the private key to establish ownership of the onion. This would be more trustworthy IMO since there would be no chance of phishing lookalikes or something akin to the "onion cloner" MITM attack. EDIT: Or simply redirecting myownfacebook420.onion to facebook.com, because that can VERY easily be done. Just add a HiddenServicePort 80 facebook.com:80 to the torrc.
- nintendo1889 12y agoThen the CA also has a copy of the private key and a malicious person could use that key.
- wowaname 12y agoHey, CAs shouldn't be trusted in the first place.
- scrollaway 12y agoHow much would a certificate like this actually cost, to someone browsing for ssl certs?
- aroch 12y agoDepends, multidomain certs aren't horribly expensive. Non-EV multidomain certs usually start around $100 and cover 3-5 domains in the "base" certificate and you can pay $10-20/year more domains. EV multidomain certs start around $300 and usually cover 3 domains and additional domains are +80/year
- lclarkmichalek 12y agooo a wildcard CN? I thought that was considered bad form. Well this makes me feel less guilty now!
- iancarroll 12y agoThere are security considerations if you run multiple services on sub domains with the same certificate, but it's frequently done for convinence.