Live data from Hacker News

StartSSL domain validation vulnerability

oalmanna.blogspot.com

31–40 of 75 posts

Re: StartSSL domain validation vulnerability

#31
post #3

This seems to an incredibly basic error for a company trusted to issue SSL certificates. How long has this vulnerability existed? Can we trust any StartSSL certificates? Will they charge for revocation, as they did with Heartbleed?

Well it was originally found 5 years ago. However StartSSL redesigned their site less then a year ago where I would guess the vulnerability came back (not that I have any knowledge to back that up).

Re: StartSSL domain validation vulnerability

#33

If this is genuine then it is absolutely inexcusable - this isn't some complex attack, that is web 101 stuff.

I came on the website expecting some complex XSS attack and I just found a form validation exploit straight from the 90's, I can't believe it was not checked...

Re: StartSSL domain validation vulnerability

#34
post #26

Earlier quoted context omitted.

> there's no reason to do business with these greedy losers What makes them greedy? That they are charging for what they do? (Serious question I am curious why you label them "greedy" and further "losers").

https://www.startssl.com/Support?v=43 They're the CA that wanted to charge $25 to revoke free certificates that were potentially compromised due to Heartbleed. Yes, it wasn't their fault, so they wouldn't be legally responsible for it, but they're acting in bad form by not offering those revocations for free for such a major issue.

Until LE, StartSSL was the cheapest option all around. Note that with their $59/year option you would get unlimited wildcard certs, amongst other things. I am not happy about this bug, and am glad I moved to LE a few weeks ago, but in the past StartSSL has saved me a ton of money, even though their website had been godawful at the time.

Re: StartSSL domain validation vulnerability

#35
I do not have appropriate words for this. What a terrible nightmare. And even worse the second time they did this. I mean what kind of company is this? I am seriously shattered that they are so careless with so much responsibility. I never liked the trusted CA system on the web but always thought you would need to be at least some state actor or serious professional in order to be able to get hold of certificates from them without validation. They should all be required to get some real security audit on everything involved, and do it again whenever there is a change or some time passed. Without they should be dropped from the list of trusted CAs. I really do not get how this happened. It is like someone did this on purpose. I am sad now.

Re: StartSSL domain validation vulnerability

#37
Too bad the author didn't issue certificates for, say, google.com, microsoft.com, and/or mozilla.org. That'd be a more likely way of getting those browser makers to put some restrictions or "sanctions" on them like Google recently did with Symantec.

Re: StartSSL domain validation vulnerability

#38

Earlier quoted context omitted.

https://www.startssl.com/Support?v=43 They're the CA that wanted to charge $25 to revoke free certificates that were potentially compromised due to Heartbleed. Yes, it wasn't their fault, so they wouldn't be legally responsible for it, but they're acting in bad form by not offering those revocations for free for such a major issue.

Until LE, StartSSL was the cheapest option all around. Note that with their $59/year option you would get unlimited wildcard certs, amongst other things. I am not happy about this bug, and am glad I moved to LE a few weeks ago, but in the past StartSSL has saved me a ton of money, even though their website had been godawful at the time.

Sure, and all that may be true, but I was specifically responding to what makes them greedy. Recommending people revoke their certificate and then hitting them with a $25 fee when they try to do so is practically the definition of such. They knew it was a serious problem, they knew all certificates could be affected (and even called it out) but then they didn't care to waive their policy in this one case even with all that taken into account. A CA who actually cared about the integrity of the system as a whole would have made a one time exception for this serious bug.

Re: StartSSL domain validation vulnerability

#39

Amongst it's repsonse, StartSSL should start logging every granted certificate to a Certificate Transparency log. From now on they need to provide the transparency so that site owners can verify there are no phony certificates being issued for their domains.

That seems appropriate. Google forced Symantec to do the same thing because of a number of misissued certificates[1].

[1]: https://security.googleblog.com/2015/10/sustaining-digital-c...

Re: StartSSL domain validation vulnerability

#40
post #14

When prompting for "postmaster", "hostmaster" or "webmaster", the values in that form should be just those and StartSSL should then put the two together ($MASTER_EMAIL + "@" + $DOMAIN.) They shouldn't assume that the "sendToEmail" value wasn't tampered with or overridden. If the original poster didn't include his screenshots or his steps then I wouldn't believe such a stupid mistake, especially one made by a certific…

For a while, I ran a small non-profit gaming site. This was well before Let's Encrypt, so we looked to StartSSL for a free certificate. They denied us.

Why?

Because we had links to a Paypal account set up to take donations. Even though PayPal had its own security, and we were only providing a link to it, that was enough for them to deny us the cert. They refused to understand that WE would be conducting no financial transactions using their service; or that PayPal was a separate entity.

It was maddening, and we ended up abandoning the whole idea of having SSL. Would that LE had existed.

Post reply on HN