Apologies if I missed it, but were they testing from a trusted source, or are some registries that wide open?
Apologies if I missed it, but were they testing from a trusted source, or are some registries that wide open?
Some registries are leaving their management systems open to the internet.
Certificate issuance doesn't need to be perfect. We have Certificate Transparency, for example to catch missisuance and CAA records to restrict the process.
I'm not shocked? The website discusses audit responsibilities quite a bit, which seems like it mitigates tampering concerns. Sure I'd prefer something other than Salesforce too, but I'm not seeing a glaring issue here.
I recently tried reporting a security issue to a ccTLD. As a registrar thankfully I was able to reach out to ICANN for assistance, but even then the person who operated the TLD had just retired and there was no replacement.
In addition, they seemed to have access to the source code, whereas the opensource version hasn't been updated in more than 8 years.
Maybe this is the result of a whitebox security audit?
Like @silisili said most of the registry operators require client certs and ips to go with the usernames but it is very possible that they are only checking that after getting a login.
CoCCA run by the tiny zones with no budgets. They are likely to be VERY vulnerable to this.