The 360 Security Lobster certificate private key was leaked; the official response states it was a business error and the certificate has been revoked.

Gate News, March 17 — The 360 Security Team responded to the security breach involving the OpenClaw wildcard certificate and private key leak. The official statement said that the leak was caused by a operational mistake, where the team accidentally packaged an internal domain certificate into the installation package. The affected certificate was *.myclaw.360.cn, which resolves to 127.0.0.1 (localhost), used only on the user's local machine and not providing any external services. After receiving reports from multiple security researchers, 360 has applied for the revocation of the certificate. The certificate is now invalid and can no longer be used for any legitimate HTTPS encrypted communication. The official statement assured that regular users are unaffected. Although there was a theoretical risk of man-in-the-middle attacks during the leak, the actual risk is limited since the certificate's service only runs in a local environment.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments