2025-09-03 12:07 UTC
Replies (6)
-
@mnordhoff@infosec.exchange 2025-09-03 12:18
@agwa Not their first one! crt.sh is especially slow right now, but IIRC there's another, expired, apparently-never-revoked cert from the same CA from ~2023. Edit: Correction: 2024-2025, and at least 1 is revoked (I did not check the others).
-
@Rairii@labyrinth.zone 2025-09-03 13:49
@agwa based on the other names, someone's been testing in production?
-
@agwa@follow.agwa.name 2025-09-04 00:13
The first rogue 1.1.1.1 certificate was issued by Fina and logged to Certificate Transparency over a year ago. AFAICT, the first person to notice any of this was Hacker News user JXzVB0iA, two days ago: https://news.ycombinator.com/item?id=45089708 This morning, it was reported to the certificate-transparency mailing list, with attribution to JXzVB0iA. A few hours later, it was reported to the mozilla-dev-security-policy mailing list, without attribution. Then Dan Goodin wrote his article, citing the mozilla-dev-security-policy post. Very surprising that Cloudflare did not notice given they operate a CT monitor.
-
@agwa@follow.agwa.name 2025-09-03 12:30
@mnordhoff Oh no, did I accidentally DDOS crtsh? That's the subject serial number which is used to identify the company in OV/EV certs. I'm guessing it's a Hungarian tax identifier.
-
@agwa@follow.agwa.name 2025-09-04 19:14
@christopherkunz These are excellent discoveries! Do you want to post this to the mozilla-dev-security-policy thread (https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc). Or I can relay them, with or without attribution.
-
@agwa@follow.agwa.name 2025-09-05 13:15
@christopherkunz Cool, thanks posting your comment in the bug. I also relayed your findings to mdsp yesterday: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc/m/hV0LJBkUAAAJ