Comment by buzer
12 hours ago
CNAME'ing pool-ntp.tesla.com to something they do not control is already quite risky as it would allow someone to e.g. request pool-ntp.tesla.com certificate though it might take quite a few tries.
12 hours ago
CNAME'ing pool-ntp.tesla.com to something they do not control is already quite risky as it would allow someone to e.g. request pool-ntp.tesla.com certificate though it might take quite a few tries.
I thought about trying this, but MPIC makes it very very very difficult (the round-robin has some geolocation magic baked in regarding what server it connects you to).
Out of curiosity, how is MPIC relevant? Not that familiar with it, but CNAME would resolve to your server regardless no?
pool-ntp.tesla.com --CNAME--> pool.ntp.org --GeoDNS--> thousands of possible servers, biased heavily by user location
1 reply →
Wouldn't the same apply to pool.ntp.org then?
Maybe running a web server on the same IP as an NTP server is a bad idea.
a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.
Hope there are no sensitive *.tesla.com cookies out there...
1 reply →
That points to a glaring hole in the modern-day automated web PKI, not Tesla's dangling DNS record.
Hell, they issue certificates to IP addresses now. For cloud systems, ownership of an IP could be a few hours.
This has almost certainly been deemed an acceptable risk.
2 replies →