🕵️ HackingReopening im Loft: Was ist neu da oben? - Wien - Kurier(17.09.2026 um 05:14 Uhr)
🕵️ HackingTangerhütte: Hacker greifen Verwaltung an - radio SAW(17.09.2026 um 06:32 Uhr)
🕵️ HackingReopening im Loft: Was ist neu da oben? - Wien - Kurier(17.09.2026 um 05:14 Uhr)
🕵️ HackingTangerhütte: Hacker greifen Verwaltung an - radio SAW(17.09.2026 um 06:32 Uhr)
📰 IT Security Nachrichten 🕛 vor 6 Jahren 2 Min Lesezeit SECURITY-FEED
0

Rant: browser handling of expired SSL certs

↗ Quelle (reddit.com)
🗣️ Stimme:


Our organization had a little crisis caused by an expired SSL cert on one host. The broken site also had HSTS enabled, so webbrowsers refused to let users bypass the invalid-certificate error.

Of course the expired cert is our fault, but still it's frustrating how all the webbrowsers handle expired certs. Invalid certificate errors are triggered by mismatched names, bad CAs, revocation, or expiration. Any error (aside from chain-order issues), and browsers seem to always hard-fail the HTTPS connection.

I don't understand why browsers don't heuristically weigh and score HTTPS certificate problems the same way SMTP servers score spam problems. It's intuitive to me that if you have an otherwise-valid certificate that was valid for 1 year, and has an expiration date only a couple of days past, then it should be evaluated differently from a cert that's revoked, or has a mismatched hostname, or a completely wrong FQDN, or a cert that is being accessed by IP but only has a SAN that matches the IP through rDNS lookup, etc. Alert the user with a pop-up depending on the severity, but don't outright declare that the website is 'not private' and steer users 'back to safety'.


submitted by [comments]
Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf reddit.com.
↗ Original-Artikel auf reddit.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
CVE-2022-44251 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUssd ussd command injection (EUVD-2022-47200)
2 Quellen
CVE-2022-44253 | TOTOLINK LR350 9.3.5u.6369_B20220309 setDiagnosisCfg via improper authentication (EUVD-2022-47202)
1 Quelle
„Gerät finden“ auf Android kann sich jetzt auf Zuruf merken, wo ihr Gegenstände abgelegt habt