Skip to content

Comment on Web Security is Too Hardparent

Comments

You'd think, but nope, it def doesn't — the site's TLS cert is issued by Google Trust Services, which issues domain-validated certs via ACME, so no, the only thing the site owner had to do to get that certificate is demonstrate ownership of the `cloudflare.pay` domain. GTS is also one of the default CAs that Cloudflare's universal SSL uses, so that's also exactly what would show up for any Cloudflare-proxied site with TLS enabled.

The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.

The domain's whois is also devoid of identifying details:

https://rdap.nominet.uk/pay/domain/cloudflare.pay

Registered through 101domain, with nothing except a registrar abuse contact.

I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.

edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.

hah thanks for the deep dive on this. I wanted to investigate myself but figured someone on HN would be faster at it. Makes sense it's not helpful, alas.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.