Daily Archives: 2025-09-03

Mis-issued certificates for 1.1.1.1 DNS service pose a threat to the Internet

Source: Ars Technica

Article note: Someone fucked up and granted a random asshole certificates for one of the most widely used DNS servers, which they most certainly do not control. Good news, not in the chain of trust for Mozilla or Google. Bad news, in the chain of trust for Microsoft. The PKI infra is always worrying when you hear about it.

People in Internet security circles are sounding the alarm over the issuance of three TLS certificates for 1.1.1.1, a widely used DNS service from content delivery network Cloudflare and the Asia Pacific Network Information Centre (APNIC) Internet registry.

The certificates, issued in May, can be used to decrypt domain lookup queries encrypted through DNS over HTTPS, a protocol that provides end-to-end encryption when end-user devices seek the IP address of a particular domain they want to access. Some security experts are also concerned that the certificates may underpin other sensitive services, such as WARP, a VPN offered by Cloudflare. The certificates remained valid at the time this post went live on Ars.

Key failures

Although the certificates were issued four months ago, their existence came to public notice only on Wednesday in a post to an online discussion forum. They were issued by Fina RDC 2020, a certificate authority that’s subordinate to the root certificate holder Fina Root CA. The Fina Root CA, in turn, is trusted by the Microsoft Root Certificate Program, which governs which certificates are trusted by the Windows operating system. Microsoft Edge accounts for approximately 5 percent of the browsers actively used on the Internet.

Read full article

Comments

Posted in News | Leave a comment