Live data from Hacker News

Ssl.com: DCV bypass and issue fake certificates for any MX hostname

bugzilla.mozilla.org

1–10 of 66 posts

Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname

#4

I guess they can check logs and find how many times this has been abused already? Can we trust them to release full transparent report?

All such certs should be in transparancy logs, so I think it should be possible for a third party to verify.

Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname

#7
post #6

So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.

It is unlikely that SSL.com would issue a certificate for any major mail host; it would be malpractice for them not to have some kind of exclusion list.

Issuing a Google certificate is a good way to get your whole CA killed.

Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname

#8
post #6

So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.

Even then, use of a DNS CAA record should mitigate this, right?

Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname

#10
post #6

So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.

Even then, use of a DNS CAA record should mitigate this, right?

Yeah - unless you're an actual SSL.com customer, in which case your CAA records would allow it. That's a much smaller blast radius at least.
Post reply on HN