Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy general
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 21st, 2012, 05:42 PM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,535
Default Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
A self-professed Iranian hacker gang announced in an online post that it compromised an SSL certificate belonging to NASA and subsequently accessed information on "thousands" of NASA researchers.

Word of the alleged hack by the Iranian Cyber Warriors Team was first reported last week by SecurityWeek , which said NASA confirmed that its security office was "investigating the claim."

A NASA spokesperson had not responded as of this posting to a press inquiry by Dark Reading on the status of the investigation.

But security experts say the hackers' claims could well be true. "[It is] absolutely possible. It was an Iranian hacker who took down DigiNotar last August. And NASA has received lots of negative GAO comments on [its] cyber" security, says Jeffrey Carr, CEO of Taia Global.

Story here.

Apologies if someone posted this already.
__________________
This space for rent.
  #2  
Old May 21st, 2012, 06:45 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Just another example of how badly broken SSL is. And the guys who did this and the Comodo hack are amatuer script kiddies.
  #3  
Old May 21st, 2012, 07:03 PM
EncryptedBytes EncryptedBytes is offline
Frequent Poster
 
Join Date: Feb 2011
Location: Odenton, Maryland
Posts: 416
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

To be fair NASA has an abysmal track record when it comes to cyber security. Something like this wouldnt surprise me.
  #4  
Old May 21st, 2012, 07:09 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by chronomatic
Just another example of how badly broken SSL is. And the guys who did this and the Comodo hack are amatuer script kiddies.
Based on what?
__________________
  #5  
Old May 22nd, 2012, 03:55 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by Hungry Man
Based on what?

Based on Moxie Marlinspike's outing of the Comdo hacker. Comdo released a statement saying it was a "very sophisticated attack from Iran, we suspect the Iranian government." Comodo released the IP addresses of the people involved to prove to everyone that it really was Iran. You know, they wanted to prove that only a sophisticated state actor could ever hack their very awesome security.

Marlinspike is a well known SSL researcher (and critic) and author of various SSL hacking tools like sslstrip and sslsniff. He checked his weblogs and discovered that the exact IP address Comodo released had visited his site the day after Comodo was hacked. What did this IP address do? It downloaded sslsniff. He checked his referrer log to see what webpages this IP was on before it visited his site and found that the person had just visited a YouTube video on "how to hack SSL." The video recommended sslstrip, so the guy went to Marlinspike's website to download it. Other interesting things is that the guy was running Windows XP and had his browser language set to English.

Moxie told this story at Black Hat 2011 and the crowd basically was ROFL'ing the entire time. He proved that the Comodo hack was not done by some sophisticated Iranian government crew, but by a kid who was literally a script kiddie (the very definition of a script kiddie actually).

So what does it say when one of the world's largest CA's gets hacked by a kid running Windows XP who watches hacker training videos on YouTube? It says we have major problems in trusting these CA's to give a **** about anything other than turning a quick profit.

You can watch the entire talk he gave about this on YouTube here:

-https://www.youtube.com/watch?v=Z7Wl2FW2TcA-

It is pretty awesome and well worth the hour. He talks about the Comodo hack and then discusses how SSL was invented and who invented it (a very interesting story in itself). Then he talks about how badly it sucks and proposes a Firefox add-on he wrote to help mitigate the issues.

I recommend starting the video at 5 minutes in because he is telling jokes until then.
  #6  
Old May 26th, 2012, 01:44 PM
hashed hashed is offline
Regular Poster
 
Join Date: May 2012
Posts: 53
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

I presume you are referring to "Convergence"? Do you actually run it? I uninstalled it because it just didn't work for me at all. I am using Perspectives instead, even though, it's not perfect either.

~h

Last edited by hashed : May 26th, 2012 at 02:20 PM.
  #7  
Old May 27th, 2012, 05:46 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Great, thanks. I hadn't heard anything about this.
__________________
  #8  
Old June 9th, 2012, 09:03 PM
Escalader's Avatar
Escalader Escalader is offline
Massive Poster
 
Join Date: Dec 2005
Location: Land of the Mooses
Posts: 3,636
Thumbs up Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

How can I get 1 source of reliable digital certificates?
__________________
Escalader
i7 8 GB RAM Notebook, 1TB External Drive
Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File
IE 9 Hardened Active X,SmartScreen,Tracking Protection
Paragon Backup and Imaging
  #9  
Old June 10th, 2012, 12:35 PM
focus focus is offline
Regular Poster
 
Join Date: Feb 2007
Posts: 103
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by Escalader
How can I get 1 source of reliable digital certificates?
+1. Also, how can I verify the ones already on my system (there are a lot) are "good"?
  #10  
Old June 10th, 2012, 04:29 PM
Escalader's Avatar
Escalader Escalader is offline
Massive Poster
 
Join Date: Dec 2005
Location: Land of the Mooses
Posts: 3,636
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by focus
+1. Also, how can I verify the ones already on my system (there are a lot) are "good"?


Exactly, short of posting what's on my IE and on FF I have no idea how to verify existing ones.

What authority is responsible for this allocation of powers to issue security certificates to vendors like Microsoft and Comodo etc?

Where does the power lie?
__________________
Escalader
i7 8 GB RAM Notebook, 1TB External Drive
Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File
IE 9 Hardened Active X,SmartScreen,Tracking Protection
Paragon Backup and Imaging
  #11  
Old June 11th, 2012, 12:13 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by Escalader
Exactly, short of posting what's on my IE and on FF I have no idea how to verify existing ones.

What authority is responsible for this allocation of powers to issue security certificates to vendors like Microsoft and Comodo etc?

Where does the power lie?

The power lies with the CA's of which there are over 600. If any CA goes rogue or gets hacked, any cert it issues can be used to MiTM any website on the Internet (as long as your browser recognizes that CA as a legit one). That's why SSL is broken -- all it takes is one CA to be compromised to ruin SSL for everyone.

As for which CA's your browser accepts, that is up to the browser vendors and they differ. Microsoft is very liberal with IE and allows a lot more CA's in its trusted store than what Mozilla or Google do.

The best protection is to use Convergence. It will use various computers around the world to make sure that all of them see the same cert (and you have the choice of picking which remote machines you trust to do this). Then it stores the cert locally on your machine and checks to make sure it doesn't change the next visit (so that it doesn't have to waste bandwidth to check each time). This is good protection against MiTM or rogue certs, and about as close to 100% protection you can get.
  #12  
Old June 11th, 2012, 02:03 PM
Escalader's Avatar
Escalader Escalader is offline
Massive Poster
 
Join Date: Dec 2005
Location: Land of the Mooses
Posts: 3,636
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by chronomatic
The power lies with the CA's of which there are over 600. If any CA goes rogue or gets hacked, any cert it issues can be used to MiTM any website on the Internet (as long as your browser recognizes that CA as a legit one). That's why SSL is broken -- all it takes is one CA to be compromised to ruin SSL for everyone.

As for which CA's your browser accepts, that is up to the browser vendors and they differ. Microsoft is very liberal with IE and allows a lot more CA's in its trusted store than what Mozilla or Google do.

The best protection is to use Convergence. It will use various computers around the world to make sure that all of them see the same cert (and you have the choice of picking which remote machines you trust to do this). Then it stores the cert locally on your machine and checks to make sure it doesn't change the next visit (so that it doesn't have to waste bandwidth to check each time). This is good protection against MiTM or rogue certs, and about as close to 100% protection you can get.


Thanks very interesting.

Can you provide more information on Convergence? a link? who else uses them? ISP's?

My question was poorly written. Let me retry. There are 600 CA approx.

Who do they/me/you apply to to have this ability to become a CA? That must be where the power lives.
__________________
Escalader
i7 8 GB RAM Notebook, 1TB External Drive
Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File
IE 9 Hardened Active X,SmartScreen,Tracking Protection
Paragon Backup and Imaging
  #13  
Old June 11th, 2012, 02:13 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Becoming a CA would be incredibly expensive because
1) No one's going to trust you at first, so browsers and OS vendors won't list you

2) You actually need to pay people to check out the websites and files

Convergence changes the system. Instead of checking a single CA for the validity of a website/ certificate you check multiple repositories, which means your trust doesn't have to rely on one single entity anymore.

It also means that attacks like SSLStripper fall flat. An attacker can spoof a certificate but with convergence you'll know it's different.
__________________
  #14  
Old June 15th, 2012, 07:23 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by Hungry Man
It also means that attacks like SSLStripper fall flat. An attacker can spoof a certificate but with convergence you'll know it's different.

Yep. I wont say it's 100% but it is close enough. It will certainly foil hackers with stolen certs, etc. It would probably even foil some government spying. But it might not work against, say, NSA who has their hooks at the backbone of the Internet and can pretty much MiTM anyone anywhere (see AT&T scandal -- NSA pretty much has access to every bit that flows over the net). So, even if you use convergence, it might be possible for them to MiTM the convergence notaries and you at the same time. Granted this probably isn't likely, but an organization with their money, influence and technical people could probably pull it off.

The only way to be 100% sure is to know the website owner personally and physically check his certificate fingerprint (sort of like you would do when signing PGP keys).
  #15  
Old June 15th, 2012, 10:08 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,047
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

i added Convergence to firefox and it blocked/alerted me on 50%~ of websites which i tried to login too (gmail etc). bug or expected behavior?
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #16  
Old June 15th, 2012, 01:20 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Iranian Hackers Claim They Compromised NASA SSL Digital Certificate

Quote:
Originally Posted by treehouse786
i added Convergence to firefox and it blocked/alerted me on 50%~ of websites which i tried to login too (gmail etc). bug or expected behavior?

It does this to me sometimes. Usually when I reload the page it works. I think what happens is the notaries are overwhelemed by traffic and sometimes time-out before they are able to verify.
 

Wilders Security Forums > Privacy Related Topics > privacy general « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:02 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums