CryptoConsortium / CCSS

The CryptoCurrency Security Standard
https://cryptoconsortium.github.io/CCSS/
139 stars 79 forks source link

Certification Verification Bug #46

Closed Enegnei closed 4 years ago

Enegnei commented 4 years ago

I discovered a problem with the certification verification / lookup option on the C4 website.

  1. Navigate down the homepage of C4, click on "Verify a Certification"
  2. On the Lookup page, enter a certification ID. For example, mine is: 5ae571. It is the ID for my Certified Bitcoin Professional (CBP) certificate.
  3. In the drop-down menu, select 'Crypto Currency Security Standard Auditor (CCSSA).'
  4. Click 'Verify.'
  5. Name, certification and expiration dates appear, as well as the message "Professional Found." This is incorrect, as that ID only applies to the CBP certification.

C4WebsiteBug

I assume the lookup is only checking whether the ID matches one in the C4 certification database, but it is ignoring what was selected in the drop-down menu. While there is probably / hopefully a low chance of this actually happening, someone could deceive a potential employer, client, etc. since the verification doesn't specify whether the ID applies to the CBP or the CCSSA certification here.

mperklin commented 4 years ago

Thanks for submitting this bug in C4's website. I'll forward it to the developer.

This repository is for discussion of the CCSS standard, and not the C4 website. As a result I will close this issue.