Skip to content

Comment on FBI entrapping hackers - using FBI self-signed SSL certparent

Comments

- Subject is invalid (and wrong)

- Overly broad (*.fbi.com) could have used "Subject Alternative Name" to list sub-domains instead.

- 3 year duration (for the FBI?). I mean for small online shops, that is fine, but many companies are now rolling their certificates yearly or bi-yearly (e.g. Amazon, Bank Of America, HSBC, etc).

On the positive side they are using a 2048 bit key length. I dunno. I guess it depends to what standard you hold the FBI up to. If you think their site should be as secure as a banking site or large online retailer then they fail at that...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.