Live data from Hacker News

Domain validated SSL certs for google.com.mg and google.com.im (not Google)

certsimple.com

21–27 of 27 posts

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#21
post #17
post #15

Earlier quoted context omitted.

> Obviously most consumers have no idea about that, and have been conditioned to trust any kind of SSL. Is that actually the case? If I see a "check for HTTPS!" reminder, most of them clearly show and talk about the name from a DV cert.

What do you mean by 'the name from a DV cert?'

typo. meant EV, where the cert owner shows up in the URL bar.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#22
post #21
post #17

Earlier quoted context omitted.

What do you mean by 'the name from a DV cert?'

typo. meant EV, where the cert owner shows up in the URL bar.

I'd love that to be the case, but I'm not sure it is.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#25
post #18

Head of Let's Encrypt here. We were aware of the "google.com.mg" cert soon after it was issued. We didn't revoke the cert for the same reason we don't revoke most certs: as far as we can tell, the cert was issued to the entity properly controlling "google.com.mg". Whether or not that is Google (the company) is not really within our purview. That said, in this case, as a courtesy, we did notify Google employees and ma…

> Whether or not that is Google (the company) is not really within our purview.

Hi Josh. This is mentioned in the third paragraph of the article, but it looks like HN didn't read that far, so probably worth mentioning it again.

I didn't mention LE specifically out of respect for the work you guys are doing, but since you've posted here: why wasn't this flagged as a High Risk Certificate Request before issuing per Baseline Requirements 4.2.1?

Also where is the High Risk Certificate Request check available in the LE source?

Thanks!

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#26
post #3

66 days later google.com.mg is still owned by not-Google, not revoked, and not on any 'safe browsing' warning lists. So? Why would a website be in safe browsing warning lists if it doesn't do anything malicious? Does Google own a trademark in Madagascar? If so, they probably can take down this domain by asking NIC-MG. If not, then, unless this website is used for phishing, I don't see any problems with issuing a cert…

> Why would a website be in safe browsing warning lists if it doesn't do anything malicious?

Some of the previous arguments in favour of DV have said that safe browsing lists will catch misissuance.

Whether DV certs are $10 or $0 doesn't make a huge difference: they don't check identity.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#27
post #26
post #3

66 days later google.com.mg is still owned by not-Google, not revoked, and not on any 'safe browsing' warning lists. So? Why would a website be in safe browsing warning lists if it doesn't do anything malicious? Does Google own a trademark in Madagascar? If so, they probably can take down this domain by asking NIC-MG. If not, then, unless this website is used for phishing, I don't see any problems with issuing a cert…

> Why would a website be in safe browsing warning lists if it doesn't do anything malicious? Some of the previous arguments in favour of DV have said that safe browsing lists will catch misissuance. Whether DV certs are $10 or $0 doesn't make a huge difference: they don't check identity.

Some of the previous arguments in favour of DV have said that safe browsing lists will catch misissuance.

Yes, so what is this website doing that warrants this measure? There was no misissuance.

Post reply on HN