Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> As you can see, StartSSL will believe you own the domain if you control webmaster@, postmaster@, or hostmaster@ with the domain name

I see a potential vuln here for free e-mail services. If one manages to register one of those addresses he can create a trusted certificate and use it for MITM.



Several paid-for certificates from a few CAs do just the same. If you're paying $0 for a certificate, don't expect more than ~$0 worth of identity checks!

It also highlights a critical SSL issue; there's really little strength in the concept of a certificate proving the identity of anyone.


That's why no free mail servers allow you to do that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: