Filippo Valsorda
· 67w
Oof. Reportedly, if you got a certificate from SSL.com by putting “example[@]gmail.com” at _validation-contactemail.example.com, they would add gmail.com (!!!) to your verified domains.
A good re...
I am curious about the disclosure timeline. I can see that SSL.com have disabled the buggy validation method, so exploitation should not be possible now.
But was this bugzilla issue visible to the public before the CA had been notified about the issue?