There's a software called "BrowserStack local", which, apparently, contains a valid certificate for bs-local[dot]com including a private key. If you leak a private key like that, and if the CA (which, in this case is Godaddy) is informed about it, they have to revoke the affected cert.
I've reported this back in November. They generated a new cert in January. Again, private key is leaked through their software.
badkeys
@badkeys@infosec.exchange
badkeys is an open-source tool and web service to identify compromised cryptographic keys.
infosec.exchange
18
0
6
Loading comments...