|
|
|
|
|
by DexesTTP
638 days ago
|
|
None of these are true for the MitM threat model that caused this whole investigation: - If someone manages to MitM the communication between e.g. Digicert and the .com WHOIS server, then they can get a signed certificate from Digicert for the domain they want - Whether you yourself used LE, Digicert or another provider doesn't have an impact, the attacker can still create such a certificate. This is pretty worrying since as an end user you control none of these things. |
|
If we were able to guarantee NO certificate authorities used WHOIS, this vector would be cut off right?
And is there not a way to, as a website visitor, tell who the certificate is from and reject/distrust ones from certain providers, e.g. Digicert? Edit: not sure if there's an extension for this, but seems to have been done before at browser level by Chrome: https://developers.google.com/search/blog/2018/04/distrust-o...