Domain validated SSL was always a bad idea. Disclaimer: I sell EV SSL validation.
Domain validated SSL was always a bad idea. Disclaimer: I sell EV SSL validation.
It's more like the way domain ownership is validated is awful. If the only way to validate domain ownership was to ask the domain owner to create a TXT entry, with both the entry name and its contents being nonces chosen by the certificate authority, it would be much harder to do these attacks (one would have to be able to MITM between the certificate authority and the domain's DNS servers, or compromise the DNS servers).
On the other hand, being able to modify the DNS records is a much stronger proof of ownership.
I strongly disagree. We need to move towards using TLS everywhere and part of doing that is making it easy for everyone to get a cert. You can validate domain control through DNS / whois records instead of the standard group of admin email address.
[1] http://arstechnica.com/security/2015/03/bogus-ssl-certificat...
The linked post talks of phone verification, but we know GSM networks don't use strong cryptography and stationary phones aren't better secured either. Do you perform any additional verification? I'd want to see use of government issued personal certs for this purpose, surprised even that this isn't commonplace.