Email or username:

Password:

Forgot your password?
Q ✨

Today in absolutely wild things: a CA abusing an RCE in ACME.sh to add their own validation methods to it! github.com/acmesh-official/acm

6 comments
gay gay kitty gay :verified_rainbow:​

@q i'm sure it sounded like a great idea in their head.

the vessel of morganna

@q lmao it asks for a crypto payment. of course it does

Flüpke

@q @julialuna they’re offering certificates for IPv4 and IPv6 addresses. While I would really love to have something this cursed, I think it’s a terrible idea, given how short-lived customers’ IP allocations typically are.

Markus

@fluepke @q @julialuna Sure. But, is that really a problem? I mean: Same for domains. No CA can ensure that you will still the owner of the (sub)domain tomorrow 🙂

Trolli Schmittlauch 🦥

@q Also rather fitting: That HiCA is affiliated to the cryprocurrency industry, demanding their payments in USD-T.

That space is rich in weird design decisions anyways.

Go Up