Live data from Hacker News

StartSSL domain validation vulnerability

oalmanna.blogspot.com

71–75 of 75 posts

Re: StartSSL domain validation vulnerability

#71
post #47

Earlier quoted context omitted.

Maybe irritating would be a better word. Or irritating that this is considered normal. The laid out attack cannot be used to attack the blog, because the blog is already so insecure.

What would HTTPS gain you or the blogger? I have literally no idea who oalmanna is, so a third-party saying oalmanna is oalmanna would be completely useless for me. I suppose it would keep a third party from knowing I read this blog, but I can't find a reason to care about that.

Well with the shit some carriers pull, from injecting personally identifiable information in HTTP headers (http://www.techrepublic.com/blog/it-security/why-are-website...) or code injection in the website content (http://www.infoworld.com/article/2925839/net-neutrality/code...), I sure benefit from an HTTPS connection everywhere...

Re: StartSSL domain validation vulnerability

#72
post #55

Earlier quoted context omitted.

From their policy: > Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only. AFAIK simply taking donations counts as "commercial purpose". You are free to dislike their policy though.

Sure, okay, but the certificate would never have been used to transact those donations. If you own a car, and you don't want dogs in your car, what does it matter if I put my dog in someone else's?

I think they just care whether or not you're making money with the site period. As in, money that could potentially go towards a paid certificate.

Re: StartSSL domain validation vulnerability

#74
post #4

> This method is rarely used, instead for the domain validation most certificate authorities ask the domain owner to place a certain file in their websites. This statement strikes me as odd. Email-based validation is the most common validation method used by most CAs for DV certificates. The only exceptions that come to mind are WoSign and Let's Encrypt. The vulnerability is pretty bad, though. Good catch.

Maybe they meant that it's rarely used even though it's widely available. Anecdotally, I think that every certificate authority I've used allows for email validation but most offer options, of which I myself prefer the file or DNS record options.

Re: StartSSL domain validation vulnerability

#75
post #47

Earlier quoted context omitted.

Maybe irritating would be a better word. Or irritating that this is considered normal. The laid out attack cannot be used to attack the blog, because the blog is already so insecure.

What would HTTPS gain you or the blogger? I have literally no idea who oalmanna is, so a third-party saying oalmanna is oalmanna would be completely useless for me. I suppose it would keep a third party from knowing I read this blog, but I can't find a reason to care about that.

Well China injected javascript malware into http pages, joining people into a botnet that launched a DDOS attack on the github pages of human rights organizations, causing github downtime.

https://citizenlab.org/2015/04/chinas-great-cannon/

Post reply on HN