Use of information collected from problem reporting addresses for marketing?

2020-06-02 Thread Benjamin Seidenberg via dev-security-policy
Greetings: Today, I received a marketing email from one of the CAs in Mozilla's program (Sectigo). As far as I know, the only interactions I've ever had with this CA where they would have gotten my name and email address would be from me submitting problem reports to them (for compromised private

Re: Entrust-issued certificate with compromised private key.

2020-01-21 Thread Benjamin Seidenberg via dev-security-policy
> One - which appears to remain valid at time of writing - is an OV certificate > for "routerlogin.com" and variants, which was issued to Netgear by Entrust, > https://crt.sh/?id=1955992027 > Based on this tweet (https://twitter.com/FiloSottile/status/1219147543667453953?s=19) from 2020-01-20