StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
The case reports that StartCom’s StartEncrypt project could be used, for about two weeks, to fraudulently obtain certificates for domains not under the user’s control, including domains such as google.com and dropbox.com. The issue was raised in the bug based on an external report (Computest) describing the vulnerability and its impact. StartCom stated that after Computest reported the problem, they fixed the bug and closed the StartEncrypt service/API the same day, and they announced this on their website. StartCom also stated that no certificates were effectively issued wrongfully due to backend checks, and that all issued certificates were correctly validated, so no certificates needed to be added to OneCRL. For future versions, StartCom decided to use the ACME protocol, and the old version was closed as of July 4. The bug is marked RESOLVED with resolution FIXED, and a later Mozilla comment notes that Mozilla took action against StartCom that included consideration of this issue.
- Bug opened describing a StartEncrypt vulnerability that could enable fraudulent certificate issuance for domains not under the user’s control.
- StartCom fixed the reported bug and closed the StartEncrypt service/API; StartEncrypt old version closed as of this date.
- StartCom reported remediation details, including that no certificates required OneCRL updates and that future service would use ACME.
- Mozilla comment indicated Mozilla took action against StartCom, including consideration of this issue.
- Community commenter — Reported that StartCom’s StartEncrypt could be used to fraudulently obtain certificates for domains not under the user’s control for about two weeks, citing an external blog post.
- Narzt representative — Expressed surprise that StartCom certificates were still being accepted and questioned whether this should lead to removal.
- Ipv representative — Pointed to an ongoing discussion in mozilla.dev.security.policy about the issue.
- Community commenter — Asked StartCom to confirm its stance and to answer questions about further actions, whether any certificates should be added to OneCRL, and the timeline for full resolution.
- Community commenter — Stated that the bug was fixed after Computest reported it, the API and StartEncrypt service were closed the same day, no certificates required OneCRL updates, and the old version was closed while future versions would use ACME.
- Community commenter — Noted that Mozilla took action against StartCom, including consideration of this issue.