惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Spread Privacy
Spread Privacy
大猫的无限游戏
大猫的无限游戏
F
Fortinet All Blogs
M
MIT News - Artificial intelligence
G
Google Developers Blog
Hacker News: Ask HN
Hacker News: Ask HN
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
H
Help Net Security
V
Visual Studio Blog
WordPress大学
WordPress大学
博客园 - 司徒正美
TaoSecurity Blog
TaoSecurity Blog
Webroot Blog
Webroot Blog
Hugging Face - Blog
Hugging Face - Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
W
WeLiveSecurity
C
CERT Recently Published Vulnerability Notes
Y
Y Combinator Blog
S
Schneier on Security
Recent Announcements
Recent Announcements
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
宝玉的分享
宝玉的分享
T
Troy Hunt's Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
Microsoft Azure Blog
Microsoft Azure Blog
N
News and Events Feed by Topic
A
About on SuperTechFans
小众软件
小众软件
K
Kaspersky official blog
Help Net Security
Help Net Security
V2EX - 技术
V2EX - 技术
P
Proofpoint News Feed
S
Secure Thoughts
IT之家
IT之家
云风的 BLOG
云风的 BLOG
N
Netflix TechBlog - Medium
The Register - Security
The Register - Security
I
Intezer
NISL@THU
NISL@THU
GbyAI
GbyAI
P
Privacy & Cybersecurity Law Blog
T
Threatpost
C
Check Point Blog
Forbes - Security
Forbes - Security
C
Cisco Blogs
AI
AI
Recorded Future
Recorded Future
F
Full Disclosure

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13 Lets encrypt certificate issued website scam Issues getting certificates for .de zone Certbot-dns-multi for dns-lego fails with request for two domains Will tlssever profile switch to 45 days next week? Certbot script searching Expired certs shut done websites Automatic renewal across multiple systems serving the same domain Account paused – Request to unpause domain exodus.digitalmansa.com Certificate for web theft phucnha.com DNS-PERSIST without spending an Order Certificate Expired, now I can't create a new one Account paused Invalid unpause URL I need to revoke a cert, how do i do this Recommended Certbot Config for 2 certs with same FQDN with different acme servers The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot Cannot load certificate "/etc/letsencrypt/live/laurexplore.fr/fullchain.pem" A small static ACME server to distribute certs Certferry - easy distribution of wildcard LE certificates Permission errors on Let's ENcrypt certificate requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot LetsEncrypt Consultation SSL/TLS certificate Issue ISRG may have received a National Security Letter or FISA Court Order? Deactivating pending authorization Perhaps this domain is at risk group and is blacklisted on the Let's Encrypt side Certificate renewal error Azuracast letsencrypt error Certbot change provider from Sectigo to CertiNext Privacy policy still mentions disabled services Letsencrypt[.]top is squatting on the LE name and acting as a web client Cert renews not working anymore Root Cert Protection and Signing Process for e.g. Intermediates or Cross-Signs of new Roots DNS Challenge failed incorrect TXT value FreeCert: a lightweight ACME management module for shared hosting and cPanel Certbot is rejecting its own specified _acme-challenge value Not able to renew certificates Issue of SSL Certificate fails Today instantly SSL certificate problems CNAME and CAA clarification Issue an SSL certificate Wacs Domain cert generation - test successful but real fails 400 Posh-acme db_error submitting renewal Safari won't trust Let's Encrypt certs Does Certbot support CNAME challenge? How does CNAME validation work vs DNS-01? Win-Acme Renewal Failing Suddenly with DNS-01 (Dreamhost) My certicate is obsokete Certbot failed to authenticate some domains ARI renewal-info Rate Limit Changes? Missing accounturi field in LE dns-persist-01 challenges Problem obtaining a certificate One cert failing to renew - don't know why Dns-persist-01 deployment status and timeline Issue (apparently) after upgrading certbot/ubuntu [nginx] IPv4 OK, IPv6 NOK Expressway ACME Certificate Renewal failing Certbot nginx challenge times out Certbot 5.5.0 Release Error unmarshaling request Try t Self-Host BitWarden - Having Issues Getting a Cert Various problems with three domains cme_registration.reg: Creating... ╷ │ Error: acme: error: 403 :: POST :: https://acme-v02.api.letsencrypt.org/acme/new-acct :: urn:ietf:params:acme:error:unauthorized :: An account with the provided public key exists but is deactivated Iran's internet outage and challenges for renewing letsencrypt certs Running multiple Certbot renewals in parallel — how to bypass the global lock file? Nginx ipv64.net Fritzbox Dietpi DNS-PERSIST-01 and _validation-persist CNAME Just a small certbot script check An easy way to publish dns-persist-01 records Problem finding dns-persist-01 in staging GoDaddy API access policy update
Possible deliberate publicly admitted violation of subscriber policy by Tom Murphy VII in the form of HTTPV
schuelermine · 2026-04-15 · via Let's Encrypt Community Support - Latest topics

April 14, 2026, 7:56pm 1

Tom Murphy VII has recently published the paper No one can force me to have a secure website!!! in the SIGBOVIK conference (direct link, conference proceedings to be published here) and accompanying YouTube video and live presentation at SIGBOVIK detailing an implementation of a deliberately insecure TLS implementation deployed to their website called HTTPV (HyperText Transport Protocol Vulnerable). They say they used multiple prime factors (more than two) to generate a RSA modulus, making it easy to factor the key on a reasonable budget. They state that the key has been signed with a Let’s Encrypt certificate.

I believe this is a willful violation of section 3.1, point 6 in the Let’s Encrypt Subscriber Agreement

By requesting, accepting, or using a Let’s Encrypt Certificate, You warrant to ISRG and the public-at-large that […] You have taken all appropriate, reasonable, and necessary steps to assure control of, secure, properly protect, and keep secret and confidential the Private Keys corresponding to the Public Keys in Your Certificates (and any associated activation data or device, e.g. password or token).

This represents a direct danger to visitors of the website and Murphy themselves. For example, they describe using their credit card number as a ServerHello.Random value, which could be stolen this way. Users could also accidentally leak data if they accidentally connect to the affected website. Hence, the certificates in question should surely be revoked.

1 Like

The website is vulnerable to Bleichenbacher's attack. If you want to revoke the website certificate, you could do it yourself by revoking the certificate's key.

Edit: It appears to have countermeasures against this attack but maybe not ROBOT.

I think I should clarify that this post was made mostly as a joke; I personally do not believe this represents an actual danger in any realistic scenario.

It has been brought to my attention that the text of the post doesn’t make this intention very clear.

While the video does state this, the veracity of the statement is not incontrovertible. The CA has not yet been "made aware of a demonstrated or proven method that can easily compute the Subscriber's Private Key" (BRs, Section 4.9.1.1, Paragraph 4). If someone were to provide such demonstration or proof (via our official problem-reporting channels), we would then be required to revoke.

The video shows that the credit card number used as such expired in 2025, although again the veracity of that statement is not incontrovertible.

Appreciated, but note that while this may be a joking matter to you, our compliance posture and continued trust depend directly on how we respond to reports like this. Please refrain from making them in jest, as they cause real work on our side.

5 Likes

Running a "real" (non-honeypot) webserver with a full Heartbleed vulnerability in 2026 is wild...

Just tested it, yup that works. This is "real" server memory alright (the code caps us to 16KiB sadly [Tom 7 Misc / SVN / [r7010] /trunk/httpv/httpv.cc, line 1405):

image

Yeah it's kinda fake as the buffer is pre-configured once we go out of bounds....

PS: Dropped my own random padding to see if we get anything more from that server, but no it's only that short string and then only zeros:

image

3 Likes

Are you certain? Line 1411-1414 of httpv.cc just fills the response with a preconfigured value.

1 Like

Yes you're right, I hadn't read far enough into the code. I was testing this first and the values were non-repeatable, but that's because it actually properly echoes the initial bytes before appending the "fake" buffer (it's been a while since I last saw a TLS server with heartbeat extension support).

2 Likes

Thanks for the clarification, it was unclear to me to what degree this forum was serious complaints and how much it was a more informal community support forum.

2 Likes

Totally understandable. This forum is largely just community support, and some amount of joking around is delightful and encouraged -- it fosters community. Unfortunately the standard for revocation is when the CA is "made aware", and different folks have had different interpretations of what exactly that means, so we try to be careful with regards to that specifically.

6 Likes