Hackers acquire Google certificate, could hijack Gmail accounts

Discussion in 'other security issues & news' started by ronjor, Aug 29, 2011.

Thread Status:
Not open for further replies.
  1. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    Two updates from GlobalSign
    Link
    Link
     
  2. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    Mozilla wants all CAs to check their systems for intrusion and report back within a week
    Mozilla Communication: Immediate action requested

    Via
     
  3. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
  4. GammaRay

    GammaRay Registered Member

    Joined:
    Sep 8, 2011
    Posts:
    1
    There's something I'd like to know. With one of those fraudulent certificates, the user would be redirected to another page that isn't Google's or would it still go straight to Google's pages? I mean, if you suspect you're being redirected, checking the IP would alert you if anything unusual is going on, right? Or am I missing something?
     
  5. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,106
    Location:
    U.S.A.
  6. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Well just remember who started it first :p

    STUXNET ring any bells ? :D
     
  7. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I would hardly call stuxnet the start of a longwinded political dispute.
     
  8. dw426

    dw426 Registered Member

    Joined:
    Jan 3, 2007
    Posts:
    5,543
    Stuxnet didn't "start" anything. It was just a much publicized confirmation that there is indeed cyber ops going on between nations. It's a daily thing all across the globe, Stuxnet just shined a big bright light on it. I have serious doubts a government is behind this certificate incident.
     
  9. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    Cyber War - by Eddy Nigg, Founder, COO/CTO of StartCom and StartSSL
    More at link
     
  10. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    Adobe: DigiNotar and the Adobe Approved Trust List (AATL)
    Adobe PSIRT: Update on DigiNotar and the Adobe Approved Trust List (AATL)

    by David Lenoe - September 8, 2011

     
  11. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,224
    Location:
    Texas
    http://reviews.cnet.com/8301-13727_...-addressed-with-snow-leopard-and-lion-updates
     
  12. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
  13. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
  14. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    GLobalSign admits security breach
    Link
     
  15. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    Dutch Government: Websites' Safety Not Guaranteed
    More at link
     
  16. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
  17. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
  18. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
  19. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    which is dated at 3 Sept 2011 ;)
     
  20. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    Hi FanJ,
    Yes I know, it's just that I was working with that service yesterday. Not sure if content of image is much relevant, anyhow it's not everyday you see a certificate for www.globalsign.com signed by www.globalsign.com
    Sorry I missed that :p
     
  21. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    GlobalSign back in operation
    More at link
     
  22. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    Quotes from Microsoft at:
    http://blogs.technet.com/b/msrc/arc...tar-certificates-and-september-bulletins.aspx

     
  23. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
  24. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
    Autotranslator:

     
  25. fsr

    fsr Registered Member

    Joined:
    Jul 26, 2010
    Posts:
    190
    DigiNotar looses their accreditation for qualified certificates, (Thu, Sep 15th)
    http://isc.sans.edu/diary.html?storyid=11590

    Latest public update from GlobalSign
    http://deck.ly/~Xh57Y

    & also related, "Symantec this week introduced what it calls the Symantec Certificate Intelligence Center"
    http://www.computerworld.com/s/arti..._based_service_seeks_out_rogue_certificates_?

    Read more about this service, download datasheets, etc at link - note: I have no affiliation with Symantec and I am not endorsing this service
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.