I'm taking this opportunity to once again ask for the widespread adoption of the Name Constraints extension in x509, and subsequent roll-out of constrained intermediate CA certs signed by a publicly trusted root. Would be so convenient to have an intermediate CA cert constrained to *.my-name.com to avoid situations like this. Being forced to either use a private PKI infrastructure or using wildcards to not leak host…
Search.chatgpt.com domain and SSL cert have been created
61–70 of 126 posts
Re: Search.chatgpt.com domain and SSL cert have been created
#62Earlier quoted context omitted.
Let’s encrypt and similar ACME compliant services allow you to get wildcard certs through their DNS-01 challenge.
A wildcard cert is an unnecessary risk, though. Just because I trust a server to hold the cert for preview.example.com doesn’t mean I’d want it to be able to pose as prod.example.com, for example.
Re: Search.chatgpt.com domain and SSL cert have been created
#63Re: Search.chatgpt.com domain and SSL cert have been created
#64I know about things like https://crt.sh but how could you be notified about something like this? Is there some service that allows you to be alerted whenever a new certificate is generated for a domain?
Re: Search.chatgpt.com domain and SSL cert have been created
#65Earlier quoted context omitted.
The point of certificate transparency is to have a public audit log of every certificate issued. Even if you had your own CA, you would be obliged to report every certificate you issue to the CT. This is a feature, not a bug.
Certificate Transparency needed to serve website owners and not some greater good. Knowing that someone issued wildcard is enough.
Because the most popular browsers (at least Chrome and Safari) generally require CT logged certificates, if you want to successfully perform a MitM attack against any user, even just some individual user, even controlling a CA, you still can't do so without publishing your fraudulent certificate to a CT log.
This is the important function of the CT log. It is an effective balance against compromised CAs and governments that might abuse CAs, because it causes such attacks to become quickly tamper-evident.
I don't think it would be possible for a system like this to be effective without publishing the actual certificate to the log.
Re: Search.chatgpt.com domain and SSL cert have been created
#66I know about things like https://crt.sh but how could you be notified about something like this? Is there some service that allows you to be alerted whenever a new certificate is generated for a domain?
You can set up your own certificate transparency listener, and get notified of every certificate created, in realtime, assuming you can handle the load. In my company we do this to scan new domains for potential phishing domains, to take them down before they become active.
Re: Search.chatgpt.com domain and SSL cert have been created
#67So does that mean my chat will be publicly searchable?
They would be open themselves to a class action lawsuit and no one would use their LLMs so I doubt it
Re: Search.chatgpt.com domain and SSL cert have been created
#68[flagged]
What makes you think an AI can't be gamed in the same ways?
Search engine spam increases the search count (apparently an important KPI), and it also increases ad impressions, both on the SERP and on the results pages.
This is a conclusion that is straight from Page and Brin themselves[1].
Re: Search.chatgpt.com domain and SSL cert have been created
#69Imagine being an innocent developer trying to spin up some internal dev tooling and accidentally landing on the front page of HN to be misinterpreted as an attack against google which could affect both stock
Re: Search.chatgpt.com domain and SSL cert have been created
#70Imagine being an innocent developer trying to spin up some internal dev tooling and accidentally landing on the front page of HN to be misinterpreted as an attack against google which could affect both stock
Ah well I like your joke, but I know GPT is moving fast, but it would be unlikely and innocent dev can change DNS records of chatgpt.com