|
|
|
|
|
by chromaxs
2309 days ago
|
|
Any CA can sign any certificate they want, including ones they generate themselves. If a bad actor got control of, or even could coerce, a CA, and could do the same for DNS, the end users would be hard pressed to know. It's a very valid attack, although minimal. To say they don't have any way of MITM'ing a connection is wrong even if it's unlikely. |
|
Chrome and Safari currently validates that a certificate has been published in the publicly available transparency logs as part of considering it valid.
Either Google doesn't publish the certificate in the logs and it's not valid, or they publish it and people are able to see the misissuance.
It's not foolproof, but it makes the attack even less likely.