iTnews
  • Home
  • News
  • Technology
  • Security

Thousands of bogus certs issued after GoDaddy bug blunder

By Juha Saarinen on Jan 12, 2017 9:52AM
Thousands of bogus certs issued after GoDaddy bug blunder

Flaw unnoticed since July last year.

Domain name registrar and hosting firm GoDaddy has been forced to revoke thousands of digital certificates this week, after a bug allowed them to be issued without proper validation.

GoDaddy senior internet product and technology leader Wayne Thayer wrote that the company had been made aware of a flaw affecting its domain validation processing system over last weekend.

The bug was introduced to GoDaddy's validation code back in July 30 last year, meaning a large number of digital certificates were subsequently issued without proper checks, Thayer admitted.

The bug was discovered by a Microsoft customer, who emailed GoDaddy about the issue last weekend.

Thayer said the bug was caused by the validation process completing succesfully even if the control check returned a HTTP 404 not found status code, when looking for the presence of data on a web page that demonstrated a customer controlled a domain.

Prior to the bug being introduced in July, the domain validation process would only complete if it received a HTTP 200 (success) code.

In total, Thayer said, 8850 certificates were issued without proper domain validation.

In the time it took for GoDaddy to investigate the bug, the number of problematic certificates went up to 8951 as a further 101 certificates were issued using cached and potentially unverified domain validation inforrmation, Thayer said.

GoDaddy has started revoking the affected certificates. Thayer said GoDaddy is not aware of "any malicious exploitation of this bug to procure a certificate for a domain that was not authorised."

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
digital certificatesencryptiongodaddysecuritysoftwaressltls

Partner Content

Why rethinking your CMS is crucial for customer retention
Promoted Content Why rethinking your CMS is crucial for customer retention
Winning strategies for complaints and disputes management in financial services
Promoted Content Winning strategies for complaints and disputes management in financial services
Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Juha Saarinen
Jan 12 2017
9:52AM
0 Comments

Related Articles

  • Police analyse 19 million messages captured in AN0M encrypted comms sting
  • Log4j vulnerabilities remain 'endemic', says US DHS
  • Post-quantum cryptography algorithms named
  • Apple introduces Lockdown Mode as it battles spyware firms
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia sets changeover date for myGov

Services Australia sets changeover date for myGov

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

NBN Co proposes to axe CVC across all plans by mid-2026

NBN Co proposes to axe CVC across all plans by mid-2026

Google Cloud IoT Core goes on the end-of-life list

Google Cloud IoT Core goes on the end-of-life list

Digital Nation

Metaverses on the agenda for Dominello, Husic ministerial meeting
Metaverses on the agenda for Dominello, Husic ministerial meeting
Criteo to fork out $94.7m for consent breaches
Criteo to fork out $94.7m for consent breaches
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
Domino’s invests in observability for zero contact delivery
Domino’s invests in observability for zero contact delivery
Australia will lose 11 percent of jobs to automation by 2040: Forrester
Australia will lose 11 percent of jobs to automation by 2040: Forrester
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.