So I tweeted them earlier and just got this response: "Hello, the tool will be removed from all our websites within the next 30 minutes. Thanks." https://twitter.com/MrTrustico/status/395905251313586176
Update: and it's gone
This seem legit...
41–50 of 64 posts
Re: This seem legit...
#42Apparently the feature is widespread: https://www.sslshopper.com/certificate-key-matcher.html http://www.ssltools.com/cert_key_match https://certificatesssl.com/ssl-tools/match-ssl-details.html http://www.mobilefish.com/services/privatekey_match_certific... http://sslchecker.com/matcher
Re: This seem legit...
#43Related: http://www.inutile.ens.fr/estatis/password-security-checker/
Re: This seem legit...
#44Related: http://www.inutile.ens.fr/estatis/password-security-checker/
Damn, this is becoming addictive.
Re: This seem legit...
#45Hello, that tool will be removed from all our websites within the next 30 minutes. Trustico Online Limited
Re: This seem legit...
#46Re: This seem legit...
#47Re: This seem legit...
#48The tool was made available for customers to legitimately check if the Private Key matched the SSL Certificate that was being installed - a common question and feature request from our customers.
However, upon review of the comments made in the internet community we have made a decision to remove this specific tool and to review all other tools that we make publicly available via our websites.
We also saw a heavy attempt to hack/abuse this tool over the past few hours, perhaps to look for exploits, an action I find absurd for those who make out to be security conscious.
I welcome any further comments on how we can improve our service and do hope that our actions to remove the tool today were prompt and satisfactory.
Zane Lucas General Manager Trustico Online Limited
Re: This seem legit...
#49I contacted their support: Me: I wanted to know more about your certificate key matcher isn't the private key always meant to remain... private? Emanuele: Yes, it should. We offer the tool to help verify the correspondence SSL certificate it is lost. Me: But it would be sent over HTTP and viewable to anyone along the network. Emanuele: The page can also be accessed through HTTPS. Me: I think it should be enforced. Al…
So leaking my private key to somebody is OK if I do so over HTTPS, and even better if I encrypt it with a javascript crypto library beforehand? I don't think you've thought this through.
I don't condone this at all, but if they're adamant about providing this service they should at least try and make it less damning than it already is.
Re: This seem legit...
#50http://www.trustico.ch/ssltools/convert/pem-key-to-der/conve...