Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Fina Root CA signs certificates for 1.1.1.1 (crt.sh)
20 points by JXzVB0iA 43 days ago | hide | past | favorite | 4 comments


This CA is trusted only by Microsoft. I and others have reported problematic CAs to Microsoft in the past (though this particular one wasn't on my radar) only for our concerns to be ignored. Mozilla, Chrome, and Apple have actual standards and don't trust CAs like this.


It's also trusted as an EU Trust Service Provider. https://eidas.ec.europa.eu/efda/trust-services/browse/eidas/... That's basically QWACS. <ins>Ah, of course you mentioned it in the other thread!</ins>


Should Cloudflare have been monitoring CT logs to spot this earlier?


We definitely should have, and that is on us. We'll fix it. https://blog.cloudflare.com/unauthorized-issuance-of-certifi...




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: