Live data from Hacker News

StartSSL domain validation vulnerability

oalmanna.blogspot.com

51–60 of 75 posts

Re: StartSSL domain validation vulnerability

#51
Arguably this vulnerability is serious enough to see StartSSL dropped from the trusted root store, or at least see browsers taking action to block DV certs from StartSSL issued before a certain date. It/they won't be, of course, since the whole system is a farce.

I'd lament again how we still need to push DANE, but I was doing that 2 days ago here on HN[0] and I'm tired of it.

Nevermind, maybe the next bug we see will be in one of the other DV methods, like tricking the validator to access a http uri of your choosing rather than '/.well-known/', for instance. Or authoritative DNS poisoning.

[0] https://news.ycombinator.com/item?id=11321184

Re: StartSSL domain validation vulnerability

#52
post #46
post #43

Earlier quoted context omitted.

Conversely, when I went for an SSL cert for my company, they called me (from Israel) on a phone number for our company taken from public sources, in order to verify we were who we were. Compare this to some other SSL providers, whose certification process is "can you give us $600?"

Was that an EV certificate? EV and DV certificates certify different things.

No, it wasn't an EV cert. It was whatever their level above the first level is (can't recall, it's been a while, but it wasn't for EV)

Re: StartSSL domain validation vulnerability

#53

Amongst it's repsonse, StartSSL should start logging every granted certificate to a Certificate Transparency log. From now on they need to provide the transparency so that site owners can verify there are no phony certificates being issued for their domains.

I'm guessing Sleevi is already dusting off his keyboard to write them a similar note.

Re: StartSSL domain validation vulnerability

#54
post #15

Meanwhile, when I tried to use them for a client's domain after actually paying $$$ for business validation I was refused because the names on the WHOIS records didn't match our business name.

I had the same problem. They did not even sign the certificate after I changed the WHOIS record and yet they kept the money.

Re: StartSSL domain validation vulnerability

#55
post #14

When prompting for "postmaster", "hostmaster" or "webmaster", the values in that form should be just those and StartSSL should then put the two together ($MASTER_EMAIL + "@" + $DOMAIN.) They shouldn't assume that the "sendToEmail" value wasn't tampered with or overridden. If the original poster didn't include his screenshots or his steps then I wouldn't believe such a stupid mistake, especially one made by a certific…

For a while, I ran a small non-profit gaming site. This was well before Let's Encrypt, so we looked to StartSSL for a free certificate. They denied us. Why? Because we had links to a Paypal account set up to take donations. Even though PayPal had its own security, and we were only providing a link to it, that was enough for them to deny us the cert. They refused to understand that WE would be conducting no financial…

From their policy:

> Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only.

AFAIK simply taking donations counts as "commercial purpose". You are free to dislike their policy though.

Re: StartSSL domain validation vulnerability

#56

OK, so this seems like a terrible vulnerability. Does anyone know if (a) StartSSL has been notified and (b) what has been their response. This seems like such a severe vulnerability that publishing it on Blogspot seems too low key. Shouldn't there be a CVE about this?

    a CVE
What would be the practical use of issuing a CVE for a vulnerability in custom code in one website? It's not like I'm going to run Nessus to scan my own network for this.

Re: StartSSL domain validation vulnerability

#57
post #5

A vulnerability of this level is inexcusable. StartSSL ought to be removed from all major browsers.

I agree. What certificates have been issued until now fraudulently like this? Does SartSSL submit certificates to Certificate Transparency? And if it does, who knows if there is a bug in that code too, and certs have not been submitted? Mozilla, Google, Apple and Microsoft should remove this CA ASAP. If it breaks some sites, even better. Maybe it will make some noise and fix all this CA bullshit for good.

IMHO this could be handled more safely: suspend or remove the acceptation of any StartSSL certificates issued after a given date. This should give them some more accountability.

Re: StartSSL domain validation vulnerability

#58
post #47

Earlier quoted context omitted.

Why is that interesting?

Maybe irritating would be a better word. Or irritating that this is considered normal. The laid out attack cannot be used to attack the blog, because the blog is already so insecure.

What would HTTPS gain you or the blogger?

I have literally no idea who oalmanna is, so a third-party saying oalmanna is oalmanna would be completely useless for me.

I suppose it would keep a third party from knowing I read this blog, but I can't find a reason to care about that.

Re: StartSSL domain validation vulnerability

#59
post #10

OK, so this seems like a terrible vulnerability. Does anyone know if (a) StartSSL has been notified and (b) what has been their response. This seems like such a severe vulnerability that publishing it on Blogspot seems too low key. Shouldn't there be a CVE about this?

It has been fixed according to the article: > In 9 March, 2016 During my research I was able to replicate the attack and issue valid certificates without verifying the ownership of the website which I will explain later in my post, the vulnerability was reported and fixed within hours.

This post needs to be higher up in the thread, and not people overreacting and demanding having them removed from browser's CA-stores etc.

Re: StartSSL domain validation vulnerability

#60

Interestingly, this blog author hasn't activated HTTPS for his own blog yet, which can be done with a single click on the Blogger settings page.

> this blog author hasn't activated HTTPS for his own blog yet,

Who the heck cares about HTTPS for a fucking blog?

Post reply on HN