Monday, November 2, 2020

Let's encrypt issuing certificates for fraudulent sites?

I want to buy a product from hyperice.com but they don't deliver to my location so while searching I find hyperice.ae which claims to be the official website for my region, the middle east.

Just to double check this I confirm with the hyperice.com chat service if they also own this other domain and turns out they do not and tell me they'll get their legal team involved.

Hyperice.ae is a fake, runs on shopify with a let's encrypt certificate. I always had the feeling let's encrypt can be misused this way and here we are.. Right?

Wouldn't a paid CA request for proof of the company and confirm the brand name etc?



No comments:

Post a Comment