The Inquirer-Home

Godaddy is fingered for dodgy SSL certificates

Elephant killer’s firm is signing certs for unqualified domain names
Thu Apr 07 2011, 13:09

MANY CERTIFICATION AUTHORITIES (CAs) are failing at their job of validating the identity of secure web servers due to their own insecure practices, according to the Electronic Frontier Foundation (EFF).

CAs are signing Secure Sockets Layer (SSL) certificates for names that are unqualified, which is a major problem because it shows that the certificates they sign are not being validated properly.

CAs should only sign public and fully qualified names on the Internet, and the existence of unqualified domain names could cause security problems due to man-in-the-middle attacks.

Using data from the EFF SSL observatory, researchers revealed how many CAs are signing unqualified names. They include the web hosting firm Godaddy, by now infamous for being led by an unabashed elephant murderer, which was "by far the worst offender".

The EFF's technology director Chris Palmer said, "The most common unqualified name is 'localhost', which always refers to your own computer!"

"It simply makes no sense for a public CA to sign a certificate for this private name. Some CAs have signed many, many certificates for this name, which indicates that they do not even keep track of which names they have signed."

In a further post, Palmer also revealed how CAs have also been signing certificates for domain names that were qualified, but completely meaningless.

The recent Comodo hack showed how important it is that CAs get it right, prodding Google into revealing the work it is doing to survey, catalogue and check SSL certificates. µ

Share this:

Comments
Open jacket

Yep it's all set up flawlessly.
But actually I'm half glad since the tighter the jacket the more certain it becomes that certain parties will feel enabled to walk all over you, and control your life and rights.
It's hard to have things work cleanly on this planet.

posted by : W.-, 08 April 2011 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?