Уровень 0 · материалов: 3
В кластер входят документы о технических и системных рисках, связанных с использованием и выдачей SSL/TLS сертификатов, и не входят документы об общих методах кибербезопасности.
Общие признаки: автоматизация SSL-сертификатов, шифрование трафика, перехват данных, безопасность HTTPS
Группа выше: HTTPS, TLS и инфраструктура сертификатов
Смысл: The core idea is that free, automated SSL certificates from Let's Encrypt have inadvertently empowered phishers by providing them with 'secure' markers (HTTPS) at scale, deceiving users who equate encryption with legitimacy.
Cybercriminals are exploiting Let's Encrypt's free SSL certificates to make thousands of PayPal phishing sites appear secure and legitimate to unsuspecting users.
Смысл: The main idea is that a significant portion of encrypted web traffic is being intercepted by both legitimate security software and malicious actors, often resulting in a net decrease in security because the interceptors use weaker encryption than the browsers they replace.
Research shows 4-10% of HTTPS traffic is intercepted, which often weakens overall security due to poor cryptographic implementations in interception tools.
Смысл: The text argues that Cloudflare's automated SSL management creates a systemic security vulnerability by ignoring RFC 8657, which could allow sophisticated attackers to obtain valid certificates through network interception, similar to the jabber.ru incident.
Cloudflare's Universal SSL implementation ignores RFC 8657's 'accounturi' parameter, leaving users vulnerable to MITM certificate issuance attacks similar to the jabber.ru breach.