Netgear Signed TLS Cert Private Key Disclosure
gist.github.com
Netgear Signed TLS Cert Private Key Disclosure
1–10 of 158 posts
Re: Netgear Signed TLS Cert Private Key Disclosure
#2Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly.
This is not what you should do as a security researcher - delete the gist until the CAs have a chance to revoke it via OCSP.
Re: Netgear Signed TLS Cert Private Key Disclosure
#3Re: Netgear Signed TLS Cert Private Key Disclosure
#4Can anyone make out what the funjsq.com is about?
Re: Netgear Signed TLS Cert Private Key Disclosure
#56 days is nowhere near a justifiable timeframe for full disclosure. Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly. This is not what you should do as a security researcher - delete the gist until the CAs h…
Though the CAs in question should probably have an automated challenge-response system to which a timed signed reply of a given message of their choice causes a revocation of the key that signed the message. (As sufficient proof of "this is vuln, kill it now, ask questions after".)
Re: Netgear Signed TLS Cert Private Key Disclosure
#6Can anyone make out what the funjsq.com is about?
Chinese gaming VPN service or something, bypasses China IP blocks to allow them to play on NA/EU servers.
Re: Netgear Signed TLS Cert Private Key Disclosure
#76 days is nowhere near a justifiable timeframe for full disclosure. Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly. This is not what you should do as a security researcher - delete the gist until the CAs h…
I think in this case it's to force browser vendors (who have the most exploitable endpoints) and companies like Apple and Microsoft at the OS level, to blacklist the offending certs. Though the CAs in question should probably have an automated challenge-response system to which a timed signed reply of a given message of their choice causes a revocation of the key that signed the message. (As sufficient proof of "this…
Re: Netgear Signed TLS Cert Private Key Disclosure
#8Earlier quoted context omitted.
Chinese gaming VPN service or something, bypasses China IP blocks to allow them to play on NA/EU servers.
I'm wondering why such a VPN service is included in the netgear firmware image? Wouldn't this resonate negatively with Chinese authorities?
Re: Netgear Signed TLS Cert Private Key Disclosure
#96 days is nowhere near a justifiable timeframe for full disclosure. Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly. This is not what you should do as a security researcher - delete the gist until the CAs h…
I think in this case it's to force browser vendors (who have the most exploitable endpoints) and companies like Apple and Microsoft at the OS level, to blacklist the offending certs. Though the CAs in question should probably have an automated challenge-response system to which a timed signed reply of a given message of their choice causes a revocation of the key that signed the message. (As sufficient proof of "this…
Re: Netgear Signed TLS Cert Private Key Disclosure
#10The only thing I can imagine here is a dedicated HSM chip... but that's overkill for a 10$ router?