Remix.run Logo
mcpherrinm 3 days ago

I couldn’t reproduce the attack with a pair of my own domains, so I think it might be even narrower in scope than the initial post suggests. But I suppose we will just have to wait to see what the CA says.

thayne 3 days ago | parent [-]

> Out of an abundance of caution, we have disabled domain validation method 3.2.2.4.14 that was used in the bug report for all SSL/TLS certificates while we investigate.

I think they have already addressed the bug.

mcpherrinm 3 days ago | parent [-]

I tested before they acknowledged or disabled the method (I was able to use a 3.2.2.4.14 validation the “normal” way)