Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

You'd think, but nope, it def doesn't — the site's TLS cert is issued by Google Trust Services, which issues domain-validated certs via ACME, so no, the only thing the site owner had to do to get that certificate is demonstrate ownership of the `cloudflare.pay` domain. GTS is also one of the default CAs that Cloudflare's universal SSL uses, so that's also exactly what would show up for any Cloudflare-proxied site with TLS enabled.

The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.

The domain's whois is also devoid of identifying details:

https://rdap.nominet.uk/pay/domain/cloudflare.pay

Registered through 101domain, with nothing except a registrar abuse contact.

I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.

edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.



hah thanks for the deep dive on this. I wanted to investigate myself but figured someone on HN would be faster at it. Makes sense it's not helpful, alas.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: