Unauthorized credential was trusted by all browsers, but Google never authorized it.
Read the whole story
Read the whole story
[url=http://meincmagazine.com/civis/viewtopic.php?p=29789705#p29789705:3r0pbfx2 said:fuzzyfuzzyfungus[/url]":3r0pbfx2]Is there some logic that I'm missing to using an absurdly high-value target for 'testing'; and doing that testing on the public internet broadly enough that you get snagged by the CTP? Or were they just playing with fire because it's more fun that way?
Huh. Who'da thunk it.Unauthorized credential was ... never authorized
[url=http://meincmagazine.com/civis/viewtopic.php?p=29789705#p29789705:ivei0dx0 said:fuzzyfuzzyfungus[/url]":ivei0dx0]Is there some logic that I'm missing to using an absurdly high-value target for 'testing'; and doing that testing on the public internet broadly enough that you get snagged by the CTP? Or were they just playing with fire because it's more fun that way?
[url=http://meincmagazine.com/civis/viewtopic.php?p=29789839#p29789839:riti2h96 said:Polyorb[/url]":riti2h96]Just weeks to the Let's Encrypt project signing certs.
Symantec did what was necessary, but it's not necessary to rely on this broken CA infrastructure.
<SMH>Among other things, the project makes it possible to detect transport layer security credentials that have been mistakenly issued by a browser-trusted certificate authority. The ability for Google employees to independently discover the unauthorized certificates so quickly is a strong endorsement of the effectiveness of the Certificate Transparency program.
[url=http://meincmagazine.com/civis/viewtopic.php?p=29789703#p29789703:3qo1818s said:kperrier[/url]":3qo1818s]But if it was for anyone else, they would have been out there for a while...
[url=http://meincmagazine.com/civis/viewtopic.php?p=29789839#p29789839:17jib89t said:Polyorb[/url]":17jib89t]Just weeks to the Let's Encrypt project signing certs.
Symantec did what was necessary, but it's not necessary to rely on this broken CA infrastructure.
Is this better?[url=http://meincmagazine.com/civis/viewtopic.php?p=29790747#p29790747:z0ppoqce said:obarthelemy[/url]":z0ppoqce][url=http://meincmagazine.com/civis/viewtopic.php?p=29789757#p29789757:z0ppoqce said:Nowicki[/url]":z0ppoqce]Lots of people want to take advantage of these kinds of errors. They will pay just about anything, and will say just about anything. So I for one am glad that this was caught, but im not convinced that all issued certs are valid. Suppose google thinks that too otherwise they wouldnt have the transparency project out there
hackers be like
![]()
Yes, let's use a picture of a black thug. Why isn't he wearing a hoodie ?
[url=http://meincmagazine.com/civis/viewtopic.php?p=29790747#p29790747:1tddnlei said:obarthelemy[/url]":1tddnlei][url=http://meincmagazine.com/civis/viewtopic.php?p=29789757#p29789757:1tddnlei said:Nowicki[/url]":1tddnlei]Lots of people want to take advantage of these kinds of errors. They will pay just about anything, and will say just about anything. So I for one am glad that this was caught, but im not convinced that all issued certs are valid. Suppose google thinks that too otherwise they wouldnt have the transparency project out there
hackers be like
![]()
Yes, let's use a picture of a black thug. Why isn't he wearing a hoodie ?
[url=http://meincmagazine.com/civis/viewtopic.php?p=29790747#p29790747:30j6tqqh said:obarthelemy[/url]":30j6tqqh][url=http://meincmagazine.com/civis/viewtopic.php?p=29789757#p29789757:30j6tqqh said:Nowicki[/url]":30j6tqqh]Lots of people want to take advantage of these kinds of errors. They will pay just about anything, and will say just about anything. So I for one am glad that this was caught, but im not convinced that all issued certs are valid. Suppose google thinks that too otherwise they wouldnt have the transparency project out there
hackers be like
![]()
Yes, let's use a picture of a black thug. Why isn't he wearing a hoodie ?
[url=http://meincmagazine.com/civis/viewtopic.php?p=29791229#p29791229:1x0qffj5 said:abridge[/url]":1x0qffj5]More interesting would be to follow where the money came from and who the certificates were actually issued to.
There should be consequences beyond merely losing a job for something like this.
Glad Google was looking.
[url=http://meincmagazine.com/civis/viewtopic.php?p=29791699#p29791699:enumk3wx said:andrew102[/url]":enumk3wx][url=http://meincmagazine.com/civis/viewtopic.php?p=29791229#p29791229:enumk3wx said:abridge[/url]":enumk3wx]More interesting would be to follow where the money came from and who the certificates were actually issued to.
There should be consequences beyond merely losing a job for something like this.
Glad Google was looking.
Why?
From the article:
" were inappropriately issued internally "
They created certificates for testing and used them internally. They got fired. Unless you have a proof they were going to sell them to someone, that's all there is to it. Not to say it's not a valid angle to look at but that's all we are being told.
What do you mean "test run?" If you're going to do this without getting caught, you don't do it like this. You issue a cert for https://www.example.com, adjust your hosts file, and run a local HTTPS server. Once you know that works, you issue the google.com cert, stick it on a thumbdrive, and sell it. At no point are you directly connecting your google.com cert to the internet to "test" it. That's just dumb.[url=http://meincmagazine.com/civis/viewtopic.php?p=29792667#p29792667:20yb42hj said:l27[/url]":20yb42hj][url=http://meincmagazine.com/civis/viewtopic.php?p=29791699#p29791699:20yb42hj said:andrew102[/url]":20yb42hj][url=http://meincmagazine.com/civis/viewtopic.php?p=29791229#p29791229:20yb42hj said:abridge[/url]":20yb42hj]More interesting would be to follow where the money came from and who the certificates were actually issued to.
There should be consequences beyond merely losing a job for something like this.
Glad Google was looking.
Why?
From the article:
" were inappropriately issued internally "
They created certificates for testing and used them internally. They got fired. Unless you have a proof they were going to sell them to someone, that's all there is to it. Not to say it's not a valid angle to look at but that's all we are being told.
It could have been a test run and they got caught big time.
[url=http://meincmagazine.com/civis/viewtopic.php?p=29793063#p29793063:4ylwogko said:Hat Monster[/url]":4ylwogko]I think firing these folk is actually an overreaction. A test pre-certificate valid for only one day isn't a threat to anyone, anywhere.
Procedure was broken, but not severely.
[url=http://meincmagazine.com/civis/viewtopic.php?p=29793845#p29793845:24p9hb9t said:JamesKatt[/url]":24p9hb9t]Issuing fake certificates so one can impersonate Google is something I'd expect the NSA to do. It makes you think about who these fired employees actually work for.
You might be right... but so does everybody else. Take Volkswagen, for example.[url=http://meincmagazine.com/civis/viewtopic.php?p=29794461#p29794461:qqlkq82g said:NetworkElf[/url]":qqlkq82g][url=http://meincmagazine.com/civis/viewtopic.php?p=29793845#p29793845:qqlkq82g said:JamesKatt[/url]":qqlkq82g]Issuing fake certificates so one can impersonate Google is something I'd expect the NSA to do. It makes you think about who these fired employees actually work for.
"What can we get away with? Will anybody notice?"
Organizations like the NSA and FBI prey on an unaware, unsuspecting public.
[url=http://meincmagazine.com/civis/viewtopic.php?p=29789755#p29789755:1gqah0sa said:Dark Pumpkin[/url]":1gqah0sa][url=http://meincmagazine.com/civis/viewtopic.php?p=29789705#p29789705:1gqah0sa said:fuzzyfuzzyfungus[/url]":1gqah0sa]Is there some logic that I'm missing to using an absurdly high-value target for 'testing'; and doing that testing on the public internet broadly enough that you get snagged by the CTP? Or were they just playing with fire because it's more fun that way?
I don't see how a certificate could be accidentally handled like that, so my first thought was someone just thought he could be sneaky and do that without getting caught. I'm not sure what value a single day certificate would have though... maybe a dare or bet?