/top/
/new/
/best/
/ask/
/show/
/job/
^
slacker news
login
about
←back to thread
A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
(follow.agwa.name)
482 points
sanqui
| 1 comments |
30 Nov 24 21:35 UTC
|
HN request time: 0.212s
|
source
Show context
sabbaticaldev
◴[
01 Dec 24 01:37 UTC
]
No.
42285451
[source]
▶
>>42284202 (OP)
#
Can someone explain what could be done with that and by whom?
replies(4):
>>42285493
#
>>42285508
#
>>42285512
#
>>42286140
#
woofcat
◴[
01 Dec 24 01:51 UTC
]
No.
42285512
[source]
▶
>>42285451
#
Whomever has this fake certificate can run a server and say it's google.com and windows will say "yep you are" with the little green lock.
replies(2):
>>42285605
#
>>42287273
#
bufferoverflow
◴[
01 Dec 24 02:13 UTC
]
No.
42285605
[source]
▶
>>42285512
#
The certificate is for a specific IP address, no?
And without DNS pointing google.com to that IP address, it's pretty useless.
replies(3):
>>42285639
#
>>42286509
#
>>42287444
#
1.
◴[
01 Dec 24 05:54 UTC
]
No.
42286509
[source]
▶
>>42285605
#
ID:
GO
↑