6 ms·
Wow I'm surprised, you're right, and it has happened before: > the attacker issued and registered a free temporary 3-month certificate for the developers[.]kak
by surround 6mo ago
Wow I'm surprised, you're right, and it has happened before:
> the attacker issued and registered a free temporary 3-month certificate for the developers[.]kakao.com domain through SSL certificate issuer called ZeroSSL. Because the routing policy was already manipulated by the BGP Hijacking, the attacker was able to register the certificate.
https://medium.com/s2wblog/post-mortem-of-klayswap-incident-through-bgp-hijacking-en-3ed7e33de600#d138:~:text=the%20attack%2C-,the,certificate,-%2E https://medium.com/s2wblog/post-mortem-of-klayswap-incident-...
- sureglymop 6mo agoYou could mitigate this by monitoring certificate transparency logs for unwanted certificates issued for your domain. Currently there are no good monitors though aka the system is a bit broken.
- pocksuppet 6mo agoAnd another one: https://notes.valdikss.org.ru/jabber.ru-mitm/ https://notes.valdikss.org.ru/jabber.ru-mitm/
- icedchai 6mo agoIt sounds like that one may have been the result of a "lawful intercept", so perhaps not necessarily BGP hijacking. If you have legitimate control of the ASN/network, it's not a hijack.