Let’s Encrypt Now Being Abused by Malvertisers
11–20 of 71 posts
Re: Let’s Encrypt Now Being Abused by Malvertisers
#12Re: Let’s Encrypt Now Being Abused by Malvertisers
#13So the traffic is encrypted. How does that make anything worse?
It seems pretty irrelevant to me if it's encrypted or not.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#14IMO the problem is more "attackers who have gained the ability to create subdomains under a legitimate domain" (not explained how) than Let's Encrypt.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#15As a CA, Let's Encrypt should only be issuing certs to second level domains. If they want to issue one to a subdomain below that, there should be a check that the second level domain approves.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#16>Let’s Encrypt only checks domains that it issues against the Google safe browsing API; in addition, they have stated that they do not believe CAs should act as a content filter. Security on the infrastructure is only possible when all critical players – browsers, CAs, and anti-virus companies – play an active role in weeding out bad actors. I agree strongly with Let's Encrypt's view. They should not be responsible f…
Isn't that what they exactly do when they check the safe browsing API?
Re: Let’s Encrypt Now Being Abused by Malvertisers
#17As a CA, Let's Encrypt should only be issuing certs to second level domains. If they want to issue one to a subdomain below that, there should be a check that the second level domain approves.
What about .co.uk ? Or the various other TLD that are 2-level deep already ? I believe it's impossible to implement this properly.
https://en.wikipedia.org/wiki/Public_Suffix_List
Probably includes https://en.wikipedia.org/wiki/List_of_Internet_top-level_dom...
Re: Let’s Encrypt Now Being Abused by Malvertisers
#18IMO the problem is more "attackers who have gained the ability to create subdomains under a legitimate domain" (not explained how) than Let's Encrypt.
There are sites that do this as part of their core ui, such as deviantart.
Because LetsEncrypt needs a very specific response to be served from a specific endpoint, you need this kind of total control to validate a domain and get a certificate issued.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#19IMO the problem is more "attackers who have gained the ability to create subdomains under a legitimate domain" (not explained how) than Let's Encrypt.
There are sites that do this as part of their core ui, such as deviantart.
Re: Let’s Encrypt Now Being Abused by Malvertisers
#20>Let’s Encrypt only checks domains that it issues against the Google safe browsing API; in addition, they have stated that they do not believe CAs should act as a content filter. Security on the infrastructure is only possible when all critical players – browsers, CAs, and anti-virus companies – play an active role in weeding out bad actors. I agree strongly with Let's Encrypt's view. They should not be responsible f…
Although it's not their responsibility, they can take steps to mitigate it.