This seems to an incredibly basic error for a company trusted to issue SSL certificates. How long has this vulnerability existed? Can we trust any StartSSL certificates? Will they charge for revocation, as they did with Heartbleed?
StartSSL domain validation vulnerability
31–40 of 75 posts
Re: StartSSL domain validation vulnerability
#32Re: StartSSL domain validation vulnerability
#33If this is genuine then it is absolutely inexcusable - this isn't some complex attack, that is web 101 stuff.
Re: StartSSL domain validation vulnerability
#34Earlier quoted context omitted.
> there's no reason to do business with these greedy losers What makes them greedy? That they are charging for what they do? (Serious question I am curious why you label them "greedy" and further "losers").
https://www.startssl.com/Support?v=43 They're the CA that wanted to charge $25 to revoke free certificates that were potentially compromised due to Heartbleed. Yes, it wasn't their fault, so they wouldn't be legally responsible for it, but they're acting in bad form by not offering those revocations for free for such a major issue.
Re: StartSSL domain validation vulnerability
#35Re: StartSSL domain validation vulnerability
#36Re: StartSSL domain validation vulnerability
#37Re: StartSSL domain validation vulnerability
#38Earlier quoted context omitted.
https://www.startssl.com/Support?v=43 They're the CA that wanted to charge $25 to revoke free certificates that were potentially compromised due to Heartbleed. Yes, it wasn't their fault, so they wouldn't be legally responsible for it, but they're acting in bad form by not offering those revocations for free for such a major issue.
Until LE, StartSSL was the cheapest option all around. Note that with their $59/year option you would get unlimited wildcard certs, amongst other things. I am not happy about this bug, and am glad I moved to LE a few weeks ago, but in the past StartSSL has saved me a ton of money, even though their website had been godawful at the time.
Re: StartSSL domain validation vulnerability
#39Amongst it's repsonse, StartSSL should start logging every granted certificate to a Certificate Transparency log. From now on they need to provide the transparency so that site owners can verify there are no phony certificates being issued for their domains.
[1]: https://security.googleblog.com/2015/10/sustaining-digital-c...
Re: StartSSL domain validation vulnerability
#40When prompting for "postmaster", "hostmaster" or "webmaster", the values in that form should be just those and StartSSL should then put the two together ($MASTER_EMAIL + "@" + $DOMAIN.) They shouldn't assume that the "sendToEmail" value wasn't tampered with or overridden. If the original poster didn't include his screenshots or his steps then I wouldn't believe such a stupid mistake, especially one made by a certific…
Why?
Because we had links to a Paypal account set up to take donations. Even though PayPal had its own security, and we were only providing a link to it, that was enough for them to deny us the cert. They refused to understand that WE would be conducting no financial transactions using their service; or that PayPal was a separate entity.
It was maddening, and we ended up abandoning the whole idea of having SSL. Would that LE had existed.