Showing posts with label digital certificates. Show all posts
Showing posts with label digital certificates. Show all posts

Wednesday, September 21, 2011

End of the road for DigiNotar as bankruptcy declared

DigiNotar gravestoneDigiNotar, the Dutch certificate authority which hackers compromised and used to generate hundreds of bogus web security certificates, has filed for bankruptcy.
The announcement that DigiNotar has filed for voluntary bankruptcy was made today by its US parent company VASCO Data Security International.
And, quite frankly, there aren't many who will be mourning its loss.
Vasco announcement of DigiNotar bankruptcy filing
VASCO's CEO, T. Kendall Hunt, seemed keen to disassociate the parent firm from the security problems seen at its subsidiary:
"We would like to remind our customers and investors that the incident at DigiNotar has no impact on VASCO's core authentication technology. The technological infrastructures of VASCO and DigiNotar remain completely separated, meaning that there is no risk for infection of VASCO's strong authentication business."
Cliff Bown, Vasco's chief financial officer, said the losses associated with DigiNotar "were expected to be significant."
It's unlikely that many people are going to shed many tears over the demise of DigiNotar. The firm lost all trust when when it was discovered that it had known that it had suffered a security breach weeks before coming clean about the problem.
But it does serve as a chilling reminder of just how fatal a hack can be for an organisation, especially if the way your corporation decides to respond to it is woefully insufficient.
The fraudulent certificates were issued in the name of major web properties such as Facebook, Twitter, Microsoft and Google; and even in the name of intelligence agencies such as the Mossad and the CIA).
For more background on the DigiNotar security scandal, make sure to take the time to listen to a recent Sophos podcast which discussed the issue featuring Sophos experts Chester Wisniewski and Mike Wood:
You can also download the podcast directly in MP3 format: Sophos Security Chet Chat 72

Tuesday, September 20, 2011

Microsoft reissues update for Win XP/2003 for DigiNotar certificate revocation


Microsoft Update on Windows XPMicrosoft had to reissue an update for users of Windows XP and Windows 2003 today related to the compromise of certificate authority DigiNotar.
It was not related to further hacking though, it appears to be a quality assurance SNAFU at the software giant.
Microsoft has updated the known issues in security advisory 2607712 to refer to an updated advisory 2616766.
KB article 2616766 points out that the update shipped last week to remove the known compromised certificates from the trusted certificate list omitted the certificates known to have been in use in the wild.
Somehow Microsoft's Patch Tuesday update only removed additional certificates issued to DigiNotar by GTE and Entrust, but did not remove the original root certificates used to intercept communications in Iran.
Users of Windows XP and 2003 with automatic updating enabled will receive the updated patch automatically, but administrators who manually deploy patches using WSUS may be required to push update 2616676 a second time.
Even worse the update requires users of XP and 2003 to reboot after applying the fixed update. Users of Windows 7, Vista, 2008 and 2008 R2 are unaffected.

Sunday, September 18, 2011

SSCC 72 - DigiNotar, DNS hijacking and Firesheep v2



Sophos Security Chet Chat logoThis week my guest for the podcast was Mike Wood, a Senior Threat Researcher at SophosLabs in Vancouver, Canada.
Mike is our expert on digital certificates and how malware authors try to use andabuse digital certificates for their own purposes.
I talked briefly about this month's Patch Tuesday, which fortunately is a small one compared to others this year.
I also briefly mentioned the compromise at DNS registrar NetNames. The attacker pointed the DNS for The Register, UPS and others to a Turkish hacker web site.
We discussed the latest version of Firesheep and how it is now able to steal your Google search history due to a flaw in how some Google sites handle cookies.
The meat of this Chet Chat was spent discussing the recent breach and impact of the hacker(s) who compromised certificate authority DigiNotar.
Mike went into some detail of how certificates have been abused and what these attackers might accomplish if they were to use bogus certificates they purloined from DigiNotar.

(8 September 2011, duration 27:22 minutes, size 12.5 MBytes)
You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 72 or subscribe to our RSS.

Monday, September 5, 2011

SSL certificate debacle includes CIA, MI6, Mossad and Tor

SpyLast week I wrote about the compromise of digital certificate authority DigiNotar. While the idea of over 250 false certificates being issued was scary, the number has grown to 531, including what could be intermediate signing certificates.
This is really bad news. As DigiNotar is a "root" certificate, they can assign authority to intermediaries to sign and validate certificates on their behalf.
It appears the attackers signed 186 certificates that could have been intermediate certificates. These certificates masqueraded as well-known certificate authorities like Thawte, Verisign, Comodo and Equifax.
The expanded list of domains for which fraudulent certificates were issued includes Facebook, Google, Microsoft, Yahoo!, Tor, Skype, Mossad, CIA, MI6, LogMeIn, Twitter, Mozilla, AOL and WordPress. A complete list can be downloaded from the Tor website.
The attackers also issued themselves certificates for *.*.com and *.*.org. I am not sure if a multi-wildcard certificate like this is valid, but if so it could allow them to impersonate anything.
Tor logoAccording to the blog post on the Tor project's website, they also left a message in Farsi. Loosely translated, it reads "great cracker, I will crack all encryption, i hate/break your head."
This incident makes me feel more justified than ever in my distrust of the certificate system. While Mozilla, Google and others have been quick to permanently remove DigiNotar as a trusted authority, in this case it is too little, too late.
Currently computer users of IE and Safari on Windows 7/Vista/2008/2008R2, or Chrome and Firefox on any platform, are protected against exploitation as long as they are fully patched.
Mac OS X users using the latest Chrome and Firefox (6.0.2) versions are fine, but Safari and OS X itself have not been patched. There are instructions on doing so on the ps | Enable blog, although it is non-trivial.
More concerning is that mobile users are being left in the dark. There have been no updates, and no manual removal method for Android or iPhone/iPad/iPod Touch users who haven't jailbroken/rooted their devices.
Tap, tap, tap... Hello, Apple? Are you there? Your competitors (Microsoft, Google, Mozilla) are protecting their customers promptly and openly. I know you don't like to talk about security, but now would be a great time to show you care.