Closed Bug 1937693 Opened 1 year ago Closed 1 year ago

DigiCert now China CCP Dog,PEM uploaded

Categories

(CA Program :: CA Security Vulnerability, task)

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: yellowwhite, Unassigned)

Details

Attachments

(2 files)

1.68 KB, application/x-x509-ca-cert
Details
4.00 KB, application/x-x509-ca-cert
Details
Attached file facebook-com.pem

User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36

Steps to reproduce:

I use a china vpn,and i am mitmed.
I view youtube.
I use latest user version firefox on Linux.

Actual results:

mitm use DIGICERT and domain is Facebook.
there is also a DIGICERT domain is *.internet.org.

Expected results:

it should not do that as a big CERT company,and must face consequences.
It should not be hide as hide donot solve mitm,publish it does.
you can email this account if you need it publish on CISA.

The certificate you've attached is for the issuing CA "DigiCert SHA2 High Assurance Server CA".

Can you share the supposed end-entity certificate for Facebook or others?

Attached file facebook-com-chain.pem

Yes.

The certificate presented appears to be valid for Facebook. It is logged in CT and details can be reviewed here - https://crt.sh/?sha256=A15C58773AC8364F32D7D5CC69AD62C842787202680ED654F391EA5927A02D64. Internet.org appears to be a domain registered by Meta Platforms, Inc. (Meta/Facebook), and internet.org redirects to meta.com with apparently another valid TLS certificate. https://crt.sh/?sha256=B3A10164D39AA878D40D3FFC5F4B1245E619DFB29D46BB5DB5A8528A7C461E34
So, I am closing this bug as invalid. I'll reopen it if the reporter can provide any additional evidence of certificate mis-issuance or CA compromise.

Status: UNCONFIRMED → RESOLVED
Type: defect → task
Closed: 1 year ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: