Elektrine lite

← Feed

@agwa@follow.agwa.name

2025-09-04 00:13 UTC

The first rogue 1.1.1.1 certificate was issued by Fina and logged to Certificate Transparency over a year ago. AFAICT, the first person to notice any of this was Hacker News user JXzVB0iA, two days ago: https://news.ycombinator.com/item?id=45089708 This morning, it was reported to the certificate-transparency mailing list, with attribution to JXzVB0iA. A few hours later, it was reported to the mozilla-dev-security-policy mailing list, without attribution. Then Dan Goodin wrote his article, citing the mozilla-dev-security-policy post. Very surprising that Cloudflare did not notice given they operate a CT monitor.

Replies (2)

  • @mnordhoff@infosec.exchange 2025-09-04 00:40

    @agwa Some goofus named Matt noticed one of the revoked certs before — I think I was searching for 1.1.1.1 on crt.sh to look at Cloudflare's certs — but didn't make a stink and then forgot about it. Wellp. Insert emoji of your choice here. Speculating wildly, I wonder if Cloudflare has monitoring but only configured it to alert on Chrome or Mozilla-trusted roots.

    Open ##1367186

  • @agwa While we're at it, is Oracle aware that Fina has also issued a certificate for 2.2.2.2 six days ago which is still valid and unrevoked? https://crt.sh/?id=20583047050

    Open ##1367188