disabling HSTS
disabling HSTS
Posted Apr 24, 2017 15:46 UTC (Mon) by gerv (guest, #3376)In reply to: disabling HSTS by linuxrocks123
Parent article: Tor exit node operator arrested in Russia (TorServers.net blog)
Well... did you know that the cert could be revoked, but even if you check the CA won't tell you because expired certificates are not required to be on any revocation lists? So this cert could have been misissued a couple of years ago, then revoked, but now it's expired the attacker is trying to use it again.
Also, did you know that when you override a cert error, you allow that cert for any SAN in it, not just the one you are connecting to? So if that cert is for www.securityblog.example.com and also www.paypal.com, you just allowed them to MITM you for paypal.com. This is more of a risk for self-signed than for expired, but I bet you didn't know it, nevertheless.
Overriding SSL cert errors, particularly with the permanent flag checked, is a _bad_ idea.
