Re: How to submit WebTrust audits in CCADB

2018-08-09 Thread jomo via dev-security-policy
I contacted CPA Canada in early 2017 about XSS and some other issues on cert.webtrust.org. They did not fix the issues but stated: > CPA Canada is currently working on upgrading the WebTrust site to > enhance the security. As of April 2018 the issues were still unfixed. I wonder if the limited ac

Re: How to submit WebTrust audits in CCADB

2018-08-09 Thread Wayne Thayer via dev-security-policy
I don't think I'm giving away any big secret by revealing that the seal website is just doing an http_referer check. If you are blocked when trying to access an audit report on cert.webtrust.org, just set the referer to the CA's domain name and refresh. You can do this with any number of Firefox ex

Re: How to submit WebTrust audits in CCADB

2018-08-09 Thread Ryan Sleevi via dev-security-policy
Thanks for the update, Kathleen. This is truly unfortunate, and unquestionably does harm to the value and brand of the WebTrust Seal, rather than provide value. On Thu, Aug 9, 2018 at 7:19 PM, Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > All, > > In t

How to submit WebTrust audits in CCADB

2018-08-09 Thread Kathleen Wilson via dev-security-policy
All, In their effort to better protect WebTrust seals, CPA Canada has made it so we can no longer access WebTrust pdf files directly from the CCADB. I received the following response when inquiring about this. “” Thank you for contacting Chartered Professional Accountants of Canada. You can no