Apple.com currently has a self-signed certificate (fixed now)
apple.com
apple.com
Correction: Qualys' tool merges tests of apple.com and www.apple.com. In fact, you've a 66% chance of getting a self-signed certificate, as the IP addresses starting with 17 are the ones serving the non-www apple.com redirect. This is clearly indicated by the "Domain" column of the table, which I apparently completely missed until just now.
Ah wait, are you only getting it on "https://apple.com"? In my Chrome browser, that immediately redirects to www.apple.com -- but if the first one was self-signed, wouldn't it be untrusted by the browser, and wouldn't the browser refuse to redirect and give me a warning instead?
Confused as to if I'm seeing the same thing as you or not.
If you use curl/wget/similar on a machine that doesn’t have Apple’s certificates installed the 301 fails (bad cert).
"curl: (60) Peer certificate cannot be authenticated with known CA certificates”
Oddly, when I first tried to load https://apple.com inside Vienna (OS X RSS reader) it refused to load (bad cert), now it loads fine. Hmmm.
Different root CA's?
OS X talks to plenty of apple.com subdomains and there really is no reason not to use self-signed certificates for this kind of thing.
so it might still scare people away, and rightfully so: normal folks cannot distinguish a self signed certificate from a malicious used one f.e. used in phishing attempts.
What do you mean with "normal folks"? Nobody can possibly distinguish this, since an attacker would also just use a self-signed certificate.
https://www.sslshopper.com/ssl-checker.html#hostname=apple.c...
https://www.sslshopper.com/ssl-checker.html#hostname=www.app...
Also, really, Apple can't figure out how to get a wildcard cert and properly install it? I had an idea at one point to put together an bot to scan and publicly shame Alexa top whatever sites if they don't do HTTPS properly and consistently. Perhaps I should go back to that idea.
Ergo, encrypt everything, and the sensitive stuff can hide in a sea of meaningless traffic.
Anyone that can do a MITM over HTTPS can really easily find the hostname of all theses IP. in fact anyone could find the hostname of theses IP....
I hear you, though, it's a real pain, but welcome to 2014, we're all learning more about crypto than we ever thought we would have to know, which is what crypto experts have been telling us for 20+ years we would have to do.
Edit: apple-store.com is obviously a real site, so let's say I find something just as legitimately looking as that.
Something more interesting: if your site provides something like a code snippet, a MITM could change it.
A lot of download sites serve downloads on http. A MITM could change out the binary. This is especially bad if you're downloading something like a library (example: zeptojs, foundation by zurb)
So yeah. There's a lot of attack vectors. Do your best to minimize it even if you can't think of anything.
1: http://en.wikipedia.org/wiki/Extended_Validation_Certificate
Screenshots: https://www.expeditedssl.com/pages/visual-security-browser-s...