Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Definitely true but this scenario worries me:

1. Get a signed cert from a recognized CA (fraudulently - not impossible).

2. Hijack the DNS (e.g., get their GoDaddy password, or point them to a DNS server you control)>.

3. The user is directed to the fake server with the fraudulently obtained cert, and does not receive a warning.



Absolutely, authentication is not bullet-proof. That's why certificate authorities have to invalidate certificates from time-to-time.


True, and of course they can only revoke the ones they know are fake. And the browser/client has to respect the revocation list.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: