Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosGoogle Cloud Tech: Gemini is coming to your city(24.09.2026 um 15:00 Uhr)
AI & KI NachrichtenGoogle’s latest moonshot to put machine learning in space(24.09.2026 um 15:12 Uhr)
Windows Tipps & SecurityPoll: What's your favorite Surface of 2026?(24.09.2026 um 14:58 Uhr)
Sichere ProgrammierungStreaming Materialized Views for Live Read Models (2026)(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA Day Is Not 86400 Seconds: The DST Bug in Your Date Math(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungSetting up Traefik: reverse proxy with automatic HTTPS(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA 200 OK response does not prove a secret leak(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungHow hot do you like it?(24.09.2026 um 15:05 Uhr)
YouTube Security VideosGoogle Cloud Tech: Gemini is coming to your city(24.09.2026 um 15:00 Uhr)
AI & KI NachrichtenGoogle’s latest moonshot to put machine learning in space(24.09.2026 um 15:12 Uhr)
Windows Tipps & SecurityPoll: What's your favorite Surface of 2026?(24.09.2026 um 14:58 Uhr)
Sichere ProgrammierungStreaming Materialized Views for Live Read Models (2026)(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA Day Is Not 86400 Seconds: The DST Bug in Your Date Math(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungSetting up Traefik: reverse proxy with automatic HTTPS(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA 200 OK response does not prove a secret leak(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungHow hot do you like it?(24.09.2026 um 15:05 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

You May Prefer to Know Less About PKI Flaws but Now Is Too Late

While you thought it was here to help all along, things like this happen all the time: A Spotify publisher was down Monday night. The culprit? A lapsed security certificate Public Key Infrastructure is pervasive and some would say it…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

While you thought it was here to help all along, things like this happen all the time: A Spotify publisher was down Monday night. The culprit? A lapsed security certificate



Public Key Infrastructure is pervasive and some would say it brings great benefits and makes the internet better. You can't disagree that being able to encrypt our connections with the websites and services we use has security and privacy benefits, but while the concept of PKI sounds good on paper, it seems to be a solution that has many issues, and has created some issues of its own.



(Note: Wireguard is a great example of how to do public key encryption without public key infrastructure)






One: PKIs Behaving Badly



You are supposed to trust PKIs. But can you really trust them? What if a PKI authority fails to verify if someone owns a domain (CertStar 2008), creates intentionally certificates for domains without the knowledge of the owner (ANSSI 2013), or it is plainly hacked and abused (Diginotar 2011). Well, apparently there is a certification for Certificate Authorities that should guarantee that they take appropriate security measures, WebTrust CA. All Certificate Authorities that are certified should be secure, right?



Diginotar, as far as you can check, was WebTrust CA certified! This means that any Certificate Authority being certified does not mean being secure. This either means that WebTrust certificate is useless or our trust in a Certificate Authority is disconnected to it being certified or not.






Two: Who can create a CA?



Anyone! The only gatekeeper for the creation of Certificate Authorities is the pre-installed root list that comes with the most popular operating systems and browsers. If you get included in the list, the user does not need to install your root certificate, which is complicated for many users. Misbehaving CAs are so problematic that a patch was necessary, Certificate Transparency.



Recent developments in EU Law will not make this problem neither better, nor worse.






Three: Who owns the digital certificate, Jekyll or Hyde?



The methods used to validate who owns an ID are different between different Certificate Authorities, an ID can be a URL, an email or any other identifier. So the level of assurance of a certificate issued by different CAs is not only different, but the final non specialist user has no way to determine what level it is.






Four: Warranty aka Responsibility



So anyone with enough money and influence can create a CA, secure it to unknown levels of security, and finally implement inconsistent methods of validation of IDs. So what degree of trust does a user get from this setup? None. No user has ever received compensation for any damage caused by a unreliable or bogus certificate. Certificate Authorities do not provide any warranty on the certificates they issue beyond being compliant with technical standards. As Ian Grigg notes, this creates a race to the bottom in certificate quality between CAs.






Five: Lack of Usability



Users should be able to check if a website is authentic, and current. But how do users, including professionals, check if they are connecting to the right website? Doing a search in a search engine, not checking the digital certificate.



Can you improve your security rotating your key more often? No, it is hardcoded by CA and industry practices. Can you rotate your key less often as your environment is low security and does not need it? Again, no you can't, and many companies suffer incidents related to certificate renewal.






Conclusion



PKI does not deliver hardly any of the benefits it is supposed to. But there is no current alternative so we are stuck with it. Why are most issues identified in PKI Problems Draft RFC version 0 gone in version 5? Are the issues solved, or perhaps there is an interest to keep them muted?



Sometimes one wonders if PKI was a clever way to prevent public key cryptography from being widely deployed to final users…. ever notice how client server side certificates are almost never used due to the many implementation hurdles?



Final note: The PKIX workgroup that publishes Digital Certificates standards has been closed for 10 years now. Are they perfect now?






Sources:



SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - You May Prefer to Know Less About PKI Flaws but Now Is Too Late
id: 769b2dda-7a36-4c22-bb20-bc2e33108d61
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "You May Prefer to Know Less Ab" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich You May Prefer to Know Less About PKI Fl.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten You May Prefer to Know Less About PKI Flaws but Now Is Too Late

Thematisch verwandte Begriffe: Prefer, Know, Less, About · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-97152 | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick