Let’s Encrypt Now Being Abused by Malvertisers
blog.trendmicro.com
Let’s Encrypt Now Being Abused by Malvertisers
1–10 of 71 posts
Re: Let’s Encrypt Now Being Abused by Malvertisers
#2There are peolpe that are really suprised? This was expected.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#3IMO the problem is more "attackers who have gained the ability to create subdomains under a legitimate domain" (not explained how) than Let's Encrypt.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#4This is not an issue, just FUD from Trend Micro.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#5>Let’s Encrypt only checks domains that it issues against the Google safe browsing API; in addition, they have stated that they do not believe CAs should act as a content filter. Security on the infrastructure is only possible when all critical players – browsers, CAs, and anti-virus companies – play an active role in weeding out bad actors.
I agree strongly with Let's Encrypt's view. They should not be responsible for policing the behaviour of their certificate users. They should just ensure that they only issue certificates for validated CNs.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#6There were already free automatically-validated CAs before Let's Encrypt.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#7As a CA, Let's Encrypt should only be issuing certs to second level domains. If they want to issue one to a subdomain below that, there should be a check that the second level domain approves.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#8Here is a more complete explanation of Let's Encrypt's views on the subject.
https://letsencrypt.org/2015/10/29/phishing-and-malware.html
Re: Let’s Encrypt Now Being Abused by Malvertisers
#9My post responding to this - https://unmitigatedrisk.com/?p=552
Re: Let’s Encrypt Now Being Abused by Malvertisers
#10Title should read "Let’s Encrypt Now Being Used by Malvertisers"
If someone gains access to a subdomain and is able to place files there, THAT is the problem, not being able to request a certificate for it.
To quote both Ford and Raymond Chen: "It rather involved being on the other side of this airtight hatchway"