Skip to content

Comment on Ssl.com: DCV bypass and issue fake certificates for any MX hostnameparent

Comments

Issuing a Google certificate is a good way to get your whole CA killed.

Surely what happened here is a good way to get your CA killed? The linked bug seems pretty bad.

Less clear on that. Bugs happen. I'm not an expert on browser root policies.

From what I understand one of the factors is how often things like this happen, and how well they handle it when it does.

Historically, singular domain validation bugs have not killed CAs.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.