New issue
Advanced search Search tips

Issue 788485 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Mark all cloudflaressl certificates as untrusted

Reported by leose...@rambler.ru, Nov 25 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47

Steps to reproduce the problem:
1. Go to any "cloudflare-protected" site (example - https://kostyakulakov.ru)
2. Look at https status

What is the expected behavior?
Browser must warn about invalid certificate because cloudflare violates end-to-end security.

What went wrong?
Browser allows cloudflare to perform MITM attack without any warning. Cloudflare can intercept and modify all traffic between site visitor and site owner.

Did this work before? No 

Chrome version: 62.0.3202.89  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

Cloudflaressl certificates must have untrusted status until Cloudflare will use end-to-end encryption between "ddos-protected" site owner and visitors.
 
Components: Internals>Network>Certificate
Labels: -Restrict-View-SecurityTeam allpublic
Status: WontFix (was: Unconfirmed)
Chrome behaves as designed. Browsers cannot be responsible for security beyond the remote endpoint, as there is no way for them to validate a given site's security practices.

Sign in to add a comment