"sslip.io's primary purpose is to assist developers who need to test against valid SSL certs, not to safeguard content."
"sslip.io's primary purpose is to assist developers who need to test against valid SSL certs, not to safeguard content."
For testing purposes you can also generate your certs valid only for a few hours/days, so you can be sure they never get used in production by accident. And with proper SAN entries.
In case it helps anyone, I wrote an openssl wrapper with a simple syntax to manage self-signed CAs: https://github.com/radiac/caman
Would you care to elaborate?
They could get a free cert other places, and even look like a real domain.
Coupled with e.g. a XSS vuln on a secured website, you could serve a nasty browser exploiting payload from a secure site, without any warning such as "this page is trying to load stuff from an unsecure site".
This in only one scenario, there are others. This really was pretty bad.
More than having the IP?
SSL is not the place to enforce content restrictions.
Yet another reason why the SSL PKI is a scam and a racket.
It's a tenuous link, but a lot better than no link at all. At times enough for law enforcement to follow the tracks.
(edit since we reached maximum comment depth) Control of an IP address doesn't mean trackable ownership of it, you could use any machine your just compromised and instantly have a valid certificate for it. Delays in certificate issue add a thin layer of security, even if you gained unlegitimate control of a domain, the interval before asking and getting a certificate offers an opportunity for the intrusion to be detected and remediated.
Instant valid certificate for any IP address you happen to compromise is really quite bad.
Why can't you do the same sort of tracking down if you have an IP?
Paying for an SSL cert does make people a bit more accountable, but I'd argue that that's a bug rather than a feature.