Skip to content

Comment on StartSSL domain validation vulnerabilityparent

Comments

I agree. What certificates have been issued until now fraudulently like this? Does SartSSL submit certificates to Certificate Transparency? And if it does, who knows if there is a bug in that code too, and certs have not been submitted?

Mozilla, Google, Apple and Microsoft should remove this CA ASAP. If it breaks some sites, even better. Maybe it will make some noise and fix all this CA bullshit for good.

IMHO this could be handled more safely: suspend or remove the acceptation of any StartSSL certificates issued after a given date. This should give them some more accountability.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.