Hacker News new | ask | show | jobs
by mcpherrinm 421 days ago
I couldn’t reproduce the attack with a pair of my own domains, so I think it might be even narrower in scope than the initial post suggests. But I suppose we will just have to wait to see what the CA says.
1 comments

> Out of an abundance of caution, we have disabled domain validation method 3.2.2.4.14 that was used in the bug report for all SSL/TLS certificates while we investigate.

I think they have already addressed the bug.

I tested before they acknowledged or disabled the method (I was able to use a 3.2.2.4.14 validation the “normal” way)