Elektrine lite

← Feed

@agwa@follow.agwa.name

2025-09-03 12:07 UTC

Hey look, another certificate authority trusted ONLY by Microsoft is issuing certificates without validation (1.1.1.1/Cloudflare DNS in this case): https://crt.sh/?sha256=D42B028468E73795365102058CBCD350AD0A0B9CA7073C5362A570C5EC208A92 (h/t Hacker News user JXzVB0iA)

Replies (6)

  • @mnordhoff@infosec.exchange 2025-09-03 12:18

    @agwa Not their first one! crt.sh is especially slow right now, but IIRC there's another, expired, apparently-never-revoked cert from the same CA from ~2023. Edit: Correction: 2024-2025, and at least 1 is revoked (I did not check the others).

    Open ##1367180

  • @Rairii@labyrinth.zone 2025-09-03 13:49

    @agwa based on the other names, someone's been testing in production?

    Open ##1367183

  • @agwa@follow.agwa.name 2025-09-04 00:13

    The first rogue 1.1.1.1 certificate was issued by Fina and logged to Certificate Transparency over a year ago. AFAICT, the first person to notice any of this was Hacker News user JXzVB0iA, two days ago: https://news.ycombinator.com/item?id=45089708 This morning, it was reported to the certificate-transparency mailing list, with attribution to JXzVB0iA. A few hours later, it was reported to the mozilla-dev-security-policy mailing list, without attribution. Then Dan Goodin wrote his article, citing the mozilla-dev-security-policy post. Very surprising that Cloudflare did not notice given they operate a CT monitor.

    Open ##1367185

  • @agwa@follow.agwa.name 2025-09-03 12:30

    @mnordhoff Oh no, did I accidentally DDOS crtsh? That's the subject serial number which is used to identify the company in OV/EV certs. I'm guessing it's a Hungarian tax identifier.

    Open ##2042593

  • @agwa@follow.agwa.name 2025-09-04 19:14

    @christopherkunz These are excellent discoveries! Do you want to post this to the mozilla-dev-security-policy thread (https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc). Or I can relay them, with or without attribution.

    Open ##2042594

  • @agwa@follow.agwa.name 2025-09-05 13:15

    @christopherkunz Cool, thanks posting your comment in the bug. I also relayed your findings to mdsp yesterday: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc/m/hV0LJBkUAAAJ

    Open ##2042595