2025-09-04 00:13 UTC
The first rogue 1.1.1.1 certificate was issued by Fina and logged to Certificate Transparency over a year ago.
AFAICT, the first person to notice any of this was Hacker News user JXzVB0iA, two days ago: https://news.ycombinator.com/item?id=45089708
This morning, it was reported to the certificate-transparency mailing list, with attribution to JXzVB0iA.
A few hours later, it was reported to the mozilla-dev-security-policy mailing list, without attribution.
Then Dan Goodin wrote his article, citing the mozilla-dev-security-policy post.
Very surprising that Cloudflare did not notice given they operate a CT monitor.
Replies (2)
-
@mnordhoff@infosec.exchange 2025-09-04 00:40
@agwa Some goofus named Matt noticed one of the revoked certs before — I think I was searching for 1.1.1.1 on crt.sh to look at Cloudflare's certs — but didn't make a stink and then forgot about it. Wellp. Insert emoji of your choice here. Speculating wildly, I wonder if Cloudflare has monitoring but only configured it to alert on Chrome or Mozilla-trusted roots.
-
@christopherkunz@chaos.social 2025-09-04 07:28
@agwa While we're at it, is Oracle aware that Fina has also issued a certificate for 2.2.2.2 six days ago which is still valid and unrevoked? https://crt.sh/?id=20583047050