StartSSL domain validation vulnerability
oalmanna.blogspot.com
StartSSL domain validation vulnerability
1–10 of 75 posts
Re: StartSSL domain validation vulnerability
#2Re: StartSSL domain validation vulnerability
#3How long has this vulnerability existed? Can we trust any StartSSL certificates? Will they charge for revocation, as they did with Heartbleed?
Re: StartSSL domain validation vulnerability
#4This statement strikes me as odd. Email-based validation is the most common validation method used by most CAs for DV certificates. The only exceptions that come to mind are WoSign and Let's Encrypt.
The vulnerability is pretty bad, though. Good catch.
Re: StartSSL domain validation vulnerability
#5Re: StartSSL domain validation vulnerability
#6A vulnerability of this level is inexcusable. StartSSL ought to be removed from all major browsers.
Re: StartSSL domain validation vulnerability
#7This seems to an incredibly basic error for a company trusted to issue SSL certificates. How long has this vulnerability existed? Can we trust any StartSSL certificates? Will they charge for revocation, as they did with Heartbleed?
Then again, I'm not exactly sure how one would go about reporting such a thing. Browser vendors have done most of the blacklisting for cases like this in the past (either by blacklisting individual certificates, or removing the root certificate completely for massive breaches). I guess I'd try my luck on one of their mailing lists or bug trackers.
If you have a regular certificate from StartSSL, there are no security implications for you because of this. (As in: for you specifically. For the CA system as a whole, this is a "Set-Your-Hair-On-Fire-And-Run-Around-Screaming-Loudly"-scenario.)
Re: StartSSL domain validation vulnerability
#8Re: StartSSL domain validation vulnerability
#9That's not just an off the cuff insult either - I find very few charitable words to describe a company that charges $25 to rekey a certificate for reasons outside the user's control, i.e. heartbleed.
More to the point, in my arrogant opinion, now that a good, free alternative exists, users in the know should pressure the browser makers to come down a lot harder on companies that let this kind of issue fly. There's no need to work through the CAB bureaucracy when, say, Google and Mozilla are probably a lot more amenable to dealing with bad (be that by ignorance or malice) actors by refusing to recognize their crappily-validated certificates.
Re: StartSSL domain validation vulnerability
#10OK, so this seems like a terrible vulnerability. Does anyone know if (a) StartSSL has been notified and (b) what has been their response. This seems like such a severe vulnerability that publishing it on Blogspot seems too low key. Shouldn't there be a CVE about this?
> In 9 March, 2016 During my research I was able to replicate the attack and issue valid certificates without verifying the ownership of the website which I will explain later in my post, the vulnerability was reported and fixed within hours.