Live data from Hacker News

Let’s Encrypt Now Being Abused by Malvertisers

blog.trendmicro.com

1–10 of 71 posts

Re: Let’s Encrypt Now Being Abused by Malvertisers

#5
>Let’s Encrypt only checks domains that it issues against the Google safe browsing API; in addition, they have stated that they do not believe CAs should act as a content filter. Security on the infrastructure is only possible when all critical players – browsers, CAs, and anti-virus companies – play an active role in weeding out bad actors.

I agree strongly with Let's Encrypt's view. They should not be responsible for policing the behaviour of their certificate users. They should just ensure that they only issue certificates for validated CNs.

Re: Let’s Encrypt Now Being Abused by Malvertisers

#10
Title should read "Let’s Encrypt Now Being Used by Malvertisers"

If someone gains access to a subdomain and is able to place files there, THAT is the problem, not being able to request a certificate for it.

To quote both Ford and Raymond Chen: "It rather involved being on the other side of this airtight hatchway"

Post reply on HN