TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

14,766 Let's Encrypt SSL Certificates Issued to PayPal Phishing Sites

12 pointsby phsourceabout 8 years ago

7 comments

mtgxabout 8 years ago
I&#x27;m not sure what&#x27;s the outrage is about here. If they don&#x27;t say PayPal before the URL, as PayPal&#x27;s EV certificate does, then why does it matter that Let&#x27;s Encrypt issued SSL certs to websites that have PayPal in their names?<p>By that logic, I would much sooner be outraged at registrars for allowing those guys to obtain domain names that put the PayPal name in the address bar. But of course even that is a silly argument, as it&#x27;s not the registrar&#x27;s job to enforce trademark protection for any company.
评论 #13956773 未加载
bndrabout 8 years ago
The certificates serve their purpose - they encrypt the traffic between the client and the website. I think Let&#x27;s Encrypt does it&#x27;s job perfectly.<p>It&#x27;s not Let&#x27;s Encrypts job to protect users from fraud.
lddabout 8 years ago
I think the issue is an issue of education.<p>When I see the &#x27;green&#x27; colour followed by the word &#x27;secure&#x27; when visiting a website using chrome, I know that this does not mean immediately that I have to trust the site. I presume the vast majority of hacker news readers will know better too. But what about the normal, average users?<p>I think we should just be more proactive in telling people what an SSL certificate <i>actually</i> is, and what https <i>guarantees</i>. Otherwise, we are not really having a discussion.
评论 #13957433 未加载
anc84about 8 years ago
I am glad Let&#x27;s Encrypt is working so well that this is viable for the scammers.
throwaway2016aabout 8 years ago
This isn&#x27;t new... there has existed DNS only SSL certificate verification for quite a while.<p>Let&#x27;s Encrypt&#x27;s only job is to not issue certificates to people who don&#x27;t own a domain. Not to ensure the content of the domain is legitimate. That&#x27;s what EV certs are for.
评论 #13957333 未加载
okketabout 8 years ago
The DNS registrars should be held accountable and informed about the abuse, they are required to act.<p><a href="https:&#x2F;&#x2F;www.icann.org&#x2F;resources&#x2F;pages&#x2F;abuse-2014-01-29-en" rel="nofollow">https:&#x2F;&#x2F;www.icann.org&#x2F;resources&#x2F;pages&#x2F;abuse-2014-01-29-en</a>
评论 #13957197 未加载
lotsoflumensabout 8 years ago
Perhaps the use of the word &quot;certificate&quot; is somewhat to blame here?<p>.. in ordinary English, a &quot;certificate&quot; is a proof or guarantee of authenticity.
评论 #13957357 未加载