home.social

#certificateauthorities — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #certificateauthorities, aggregated by home.social.

  1. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  2. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  3. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  4. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  5. Just about the entire internet uses certificate authorities to establish trust. Here, a simple old-school social engineering trick broke this trust and allowed hackers to get signed certificates from DigiCert for their malware.

    There is a better way to establish certificate trust that doesn't rely on a 3rd party, and it's free too. It's called DANE, which binds the trust directly to the Domain Name System by using DNSSEC. DANE is ideal for code signing certificates (and other uses), but is overlooked.

    This attack is virtually impossible under DANE. A vulnerable support person is of no use. Hackers would need to directly compromise the target's DNS infrastructure, the registrar, and the top-level domain authority. All three. Nearly impossible compared to just finding some dupe at the CA in a public chat room.

    hackread.com/hackers-digicert-

    #DANE #CertificateAuthorities #DigiCert

  6. 2 #CertificateAuthorities booted from the good graces of #Chrome

    #Google says its Chrome browser will stop trusting certificates from two certificate authorities after “patterns of concerning behavior observed over the past year” diminished trust in their reliability.

    The 2 orgs, #Taiwan -based #ChunghwaTelecom & #Budapest -based #Netlock , are among the hundreds of cert auth trusted by Chrome & most other #browsers to provide digital certificates that #encrypt traffic

    arstechnica.com/security/2025/

  7. 2 #CertificateAuthorities booted from the good graces of #Chrome

    #Google says its Chrome browser will stop trusting certificates from two certificate authorities after “patterns of concerning behavior observed over the past year” diminished trust in their reliability.

    The 2 orgs, #Taiwan -based #ChunghwaTelecom & #Budapest -based #Netlock , are among the hundreds of cert auth trusted by Chrome & most other #browsers to provide digital certificates that #encrypt traffic

    arstechnica.com/security/2025/

  8. CW: non-techie web hosting ideas

    @wyatwerp
    The signing and #HTTPS is another very good point, yes. And justification for moving to the New Internet.

    The #legacyInternet requires trust in third parties known as #certificateAuthorities. The 'NewInternet' does not require this #trust.

    The New Internet is quite vibrant and seems to be always growing. It needs to be the future - and thus will be.

    #trustless #censorshipResistant #censorship