5 ms·
The Guardian also open-sourced a test SSL cert
- vxxzy 13y agoThis is just a self-signed cert.
- untog 13y agoBefore everyone gets hysterical, please vote ^^^ that comment up. It's a self-signed cert, it is not used in production: https://news.ycombinator.com/item?id=6875023 https://news.ycombinator.com/item?id=6875023
- bradleybuda 13y agoYep. Though it opens up a (probably hypothetical) potential attack if this cert is widely trusted on, say, Guardian employees' development machines.
- sgtpepper 13y agoThey updated it with this comment > this is a TEST key for local development - NOT an important key
- anilshanbhag 13y agoSo now anyone snooping on visitors to Guardian's site can decrypt the communication. Don't see why anyone would waste time on this given that there is no 'money' involved.
- ctz 13y agoIssuer: C=GB, ST=London, L=London, O=GU, OU=tech, CN=*.int.gnl/emailAddress=martyn.inglis@guardian.co.uk Subject: C=GB, ST=London, L=London, O=GU, OU=tech, CN=*.int.gnl/emailAddress=martyn.inglis@guardian.co.uk This isn't the Guardian's certificate. It's self-signed, for starters.
- clone1018 13y agoWouldn't this allow someone to do a full man in the middle attack with a compromised server/dns server?
- pritambaral 13y agoIf it were the actual cert they're using, yes.
- clone1018 13y agoOh I see now that it's just the self signed cert. Awesome :)
- deleted 13y ago[deleted]
- quasse 13y agoHTTPS does not seem to be properly configured on their servers anyway, I get an "You attempted to reach www.theguardian.com, but instead you actually reached a server identifying itself as *.a.ssl.fastly.net." error when trying to connect over HTTPS. That's interesting because they do have content protected by a sign in system. Are they just not using HTTPS for that? I kind of expected more from the Guardian.
- lotsofcows 13y agoIt's a CDN. CloudFlare operates the same way.
- boyander 13y agoYes, just checked now.
- deleted 13y ago[deleted]
- samuel1604 13y agoit's not the real one it's a test SSL cert