TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

ZeroSSL: XSS to session hijacking, stealing a private key (and password hash)

112 pointsby kkmover 2 years ago

6 comments

agwaover 2 years ago
Important note: ZeroSSL is <i>not</i> a certificate authority but a certificate reseller who is paying an actual CA, Sectigo, to operate a white-label intermediate certificate with ZeroSSL in the name[1].<p>As a non-CA, ZeroSSL isn&#x27;t required to provide an incident report or revoke any certificates like the researcher is requesting. Fortunately, their bad security can only impact their own customers, in contrast to a CA whose bad security can affect everyone.<p>[1] see <a href="https:&#x2F;&#x2F;www.agwa.name&#x2F;blog&#x2F;post&#x2F;the_certificate_issuer_field_is_a_lie" rel="nofollow">https:&#x2F;&#x2F;www.agwa.name&#x2F;blog&#x2F;post&#x2F;the_certificate_issuer_field...</a>
评论 #34447369 未加载
sys42590over 2 years ago
ZeroSSL left an uncanny impression on me when for some reason acme.sh developers made them default instead of Let&#x27;s Encrypt. This prompted me to switch to a different client (just in case of further worsening of Let&#x27;s Encrypt support by acme.sh).
评论 #34448878 未加载
评论 #34449074 未加载
评论 #34445769 未加载
Ayeshover 2 years ago
Before 2020, ZeroSSL used to be a browser-based acme client using Lets Encrypt. I don&#x27;t doubt that money was involved, and they switched to Comodo (now Sectigo), with no notice that I could think of. I used them for a few one-off certificates, but this rug-pull caught me off guard. I&#x27;d happily watch if they go down in this dumpster fire.
greyhound_7over 2 years ago
ZeroSSL is pretty much the worst. If you need TLS certs, don&#x27;t use them.
评论 #34448497 未加载
评论 #34448062 未加载
hit8runover 2 years ago
Hmm… I’m wondering if this a security flaw on purpose so the NSA or other authorities have an easy backdoor?
egberts1over 2 years ago
Dehydrated.io, damn few dependencies.<p>You&#x27;re welcome.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;dehydrated-io&#x2F;dehydrated">https:&#x2F;&#x2F;github.com&#x2F;dehydrated-io&#x2F;dehydrated</a>
评论 #34471068 未加载
评论 #34446180 未加载