惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
Cyberwarzone
Cyberwarzone
博客园_首页
爱范儿
爱范儿
腾讯CDC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
K
Kaspersky official blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
S
SegmentFault 最新的问题
L
LINUX DO - 热门话题
T
Tenable Blog
P
Privacy & Cybersecurity Law Blog
N
News | PayPal Newsroom
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
LangChain Blog
L
Lohrmann on Cybersecurity
P
Palo Alto Networks Blog
云风的 BLOG
云风的 BLOG
A
Arctic Wolf
N
News and Events Feed by Topic
AWS News Blog
AWS News Blog
美团技术团队
U
Unit 42
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
S
Secure Thoughts
有赞技术团队
有赞技术团队
C
Cyber Attacks, Cyber Crime and Cyber Security
Schneier on Security
Schneier on Security
Cloudbric
Cloudbric
B
Blog
NISL@THU
NISL@THU
Help Net Security
Help Net Security
Y
Y Combinator Blog
J
Java Code Geeks
S
Securelist
宝玉的分享
宝玉的分享
T
Threat Research - Cisco Blogs
S
Security @ Cisco Blogs
O
OpenAI News
D
DataBreaches.Net
Know Your Adversary
Know Your Adversary
Hacker News - Newest:
Hacker News - Newest: "LLM"
Vercel News
Vercel News
Forbes - Security
Forbes - Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13 Lets encrypt certificate issued website scam Issues getting certificates for .de zone Certbot-dns-multi for dns-lego fails with request for two domains Will tlssever profile switch to 45 days next week? Certbot script searching Expired certs shut done websites Automatic renewal across multiple systems serving the same domain Account paused – Request to unpause domain exodus.digitalmansa.com Certificate for web theft phucnha.com DNS-PERSIST without spending an Order Certificate Expired, now I can't create a new one Account paused Invalid unpause URL I need to revoke a cert, how do i do this Recommended Certbot Config for 2 certs with same FQDN with different acme servers The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot Cannot load certificate "/etc/letsencrypt/live/laurexplore.fr/fullchain.pem" A small static ACME server to distribute certs Certferry - easy distribution of wildcard LE certificates Permission errors on Let's ENcrypt certificate requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot LetsEncrypt Consultation SSL/TLS certificate Issue ISRG may have received a National Security Letter or FISA Court Order? Deactivating pending authorization Perhaps this domain is at risk group and is blacklisted on the Let's Encrypt side Certificate renewal error Azuracast letsencrypt error Certbot change provider from Sectigo to CertiNext Privacy policy still mentions disabled services Letsencrypt[.]top is squatting on the LE name and acting as a web client Cert renews not working anymore Root Cert Protection and Signing Process for e.g. Intermediates or Cross-Signs of new Roots DNS Challenge failed incorrect TXT value FreeCert: a lightweight ACME management module for shared hosting and cPanel Certbot is rejecting its own specified _acme-challenge value Not able to renew certificates Issue of SSL Certificate fails Today instantly SSL certificate problems CNAME and CAA clarification Issue an SSL certificate Wacs Domain cert generation - test successful but real fails 400 Posh-acme db_error submitting renewal Safari won't trust Let's Encrypt certs Does Certbot support CNAME challenge? How does CNAME validation work vs DNS-01? Win-Acme Renewal Failing Suddenly with DNS-01 (Dreamhost) My certicate is obsokete Certbot failed to authenticate some domains ARI renewal-info Rate Limit Changes? Missing accounturi field in LE dns-persist-01 challenges Problem obtaining a certificate One cert failing to renew - don't know why Dns-persist-01 deployment status and timeline Issue (apparently) after upgrading certbot/ubuntu [nginx] IPv4 OK, IPv6 NOK Expressway ACME Certificate Renewal failing Certbot nginx challenge times out Certbot 5.5.0 Release Error unmarshaling request Try t Self-Host BitWarden - Having Issues Getting a Cert Various problems with three domains cme_registration.reg: Creating... ╷ │ Error: acme: error: 403 :: POST :: https://acme-v02.api.letsencrypt.org/acme/new-acct :: urn:ietf:params:acme:error:unauthorized :: An account with the provided public key exists but is deactivated Iran's internet outage and challenges for renewing letsencrypt certs Running multiple Certbot renewals in parallel — how to bypass the global lock file? Nginx ipv64.net Fritzbox Dietpi DNS-PERSIST-01 and _validation-persist CNAME Just a small certbot script check An easy way to publish dns-persist-01 records Problem finding dns-persist-01 in staging GoDaddy API access policy update
Possible deliberate publicly admitted violation of subscriber policy by Tom Murphy VII in the form of HTTPV
schuelermine · 2026-04-15 · via Let's Encrypt Community Support - Latest topics

April 14, 2026, 7:56pm 1

Tom Murphy VII has recently published the paper No one can force me to have a secure website!!! in the SIGBOVIK conference (direct link, conference proceedings to be published here) and accompanying YouTube video and live presentation at SIGBOVIK detailing an implementation of a deliberately insecure TLS implementation deployed to their website called HTTPV (HyperText Transport Protocol Vulnerable). They say they used multiple prime factors (more than two) to generate a RSA modulus, making it easy to factor the key on a reasonable budget. They state that the key has been signed with a Let’s Encrypt certificate.

I believe this is a willful violation of section 3.1, point 6 in the Let’s Encrypt Subscriber Agreement

By requesting, accepting, or using a Let’s Encrypt Certificate, You warrant to ISRG and the public-at-large that […] You have taken all appropriate, reasonable, and necessary steps to assure control of, secure, properly protect, and keep secret and confidential the Private Keys corresponding to the Public Keys in Your Certificates (and any associated activation data or device, e.g. password or token).

This represents a direct danger to visitors of the website and Murphy themselves. For example, they describe using their credit card number as a ServerHello.Random value, which could be stolen this way. Users could also accidentally leak data if they accidentally connect to the affected website. Hence, the certificates in question should surely be revoked.

1 Like

The website is vulnerable to Bleichenbacher's attack. If you want to revoke the website certificate, you could do it yourself by revoking the certificate's key.

Edit: It appears to have countermeasures against this attack but maybe not ROBOT.

I think I should clarify that this post was made mostly as a joke; I personally do not believe this represents an actual danger in any realistic scenario.

It has been brought to my attention that the text of the post doesn’t make this intention very clear.

While the video does state this, the veracity of the statement is not incontrovertible. The CA has not yet been "made aware of a demonstrated or proven method that can easily compute the Subscriber's Private Key" (BRs, Section 4.9.1.1, Paragraph 4). If someone were to provide such demonstration or proof (via our official problem-reporting channels), we would then be required to revoke.

The video shows that the credit card number used as such expired in 2025, although again the veracity of that statement is not incontrovertible.

Appreciated, but note that while this may be a joking matter to you, our compliance posture and continued trust depend directly on how we respond to reports like this. Please refrain from making them in jest, as they cause real work on our side.

5 Likes

Running a "real" (non-honeypot) webserver with a full Heartbleed vulnerability in 2026 is wild...

Just tested it, yup that works. This is "real" server memory alright (the code caps us to 16KiB sadly [Tom 7 Misc / SVN / [r7010] /trunk/httpv/httpv.cc, line 1405):

image

Yeah it's kinda fake as the buffer is pre-configured once we go out of bounds....

PS: Dropped my own random padding to see if we get anything more from that server, but no it's only that short string and then only zeros:

image

3 Likes

Are you certain? Line 1411-1414 of httpv.cc just fills the response with a preconfigured value.

1 Like

Yes you're right, I hadn't read far enough into the code. I was testing this first and the values were non-repeatable, but that's because it actually properly echoes the initial bytes before appending the "fake" buffer (it's been a while since I last saw a TLS server with heartbeat extension support).

2 Likes

Thanks for the clarification, it was unclear to me to what degree this forum was serious complaints and how much it was a more informal community support forum.

2 Likes

Totally understandable. This forum is largely just community support, and some amount of joking around is delightful and encouraged -- it fosters community. Unfortunately the standard for revocation is when the CA is "made aware", and different folks have had different interpretations of what exactly that means, so we try to be careful with regards to that specifically.

6 Likes