Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you are your hoster and can reroute requests, you can get all kinds of valid SSL certs for any domains that you host.

Just grab these IP packets when CA comes to validate that you own that domain. Perhaps EV could solve that to some extent but it is never mandated.

Even if you tried to put any stuff into WHOIS to mitigate this, your hoster can serve any bullshit on this channel too.

It does look very bad and SSH approach to certificates is just infinitely better. If Jabber used SSL keys instead, they will be alerted immediately.

Come to think of it, your hoster can also find ways to steal keys directly from hardware, though.



Step 1: Become a hoster popular enough that interesting targets are being hosted there


If you're a government you may just bully existing ones.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: