Skip to content

Comment on Ssl.com: DCV bypass and issue fake certificates for any MX hostnameparent

Comments

I couldn’t reproduce the attack with a pair of my own domains, so I think it might be even narrower in scope than the initial post suggests. But I suppose we will just have to wait to see what the CA says.

Out of an abundance of caution, we have disabled domain validation method 3.2.2.4.14 that was used in the bug report for all SSL/TLS certificates while we investigate.

I think they have already addressed the bug.

I tested before they acknowledged or disabled the method (I was able to use a 3.2.2.4.14 validation the “normal” way)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.