![]() |
|
#1
|
|||
|
|||
|
Quote:
Article |
|
#2
|
|||
|
|||
|
Lesson: Check hashes on these certs
A related story posted a while back is in this thread. There I break down a lot of reasons why I think this latest fear mongering over rogue peeps jacking certs is vastly overstated and overall is nothing to worry about if basic precautions (i.e., checking hashes) are taken. |
|
#3
|
||||
|
||||
|
I'd wouldn't really call this an issue, the screenshots themselves show that the certificates are infact invalid.
I'd be far more concerned over malware like stuxnet that managed to get Realtek's actual key and signed their malware with a valid certificate, Microsoft had to invalidate that certificate from Verisign.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#4
|
|||
|
|||
|
Quote:
Realtek peeps are idiots then. They should never store their master key in a place where malware can touch it. Furthermore, the malware would have to have some way of cracking the key's passphrase (unless the private key had no passphrase, which is total idiocy). Let me add, that this non-story the OP posted is nothing but a way for Trend Micro to attempt to make Kaspersky look bad (even though Kaspersky did nothing wrong whatsoever and this "issue" is indeed a non-issue). The hashes don't match. I mean that's what hashes are for. Everything is working as it's supposed to work! This is actually a very retarded story. "Full retard" at that. ![]() |
|
#5
|
|||
|
|||
|
There is a thread already for that subject. Please continue the conversation there instead.
http://www.wilderssecurity.com/showthread.php?t=278822 Thanks.
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Maya, My Dearest Beloved Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4 |
|
#6
|
||||
|
||||
|
Quote:
I agree. Quote:
Well it's not confirmed how they got Realtek's key but some people believe blackmail/goverments were involved. I believe they got a key from another Taiwanese company also.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|