2011-09-13 submit to reddit

Latest on Certificate Hacking

Recent computer hacks against the security of providers of digital certificates, the lifeblood of secure web access, have prompted responses this week from both those providers and from the Internet browser makers who attest to the security of those certificates.

First, some background for those of you who might be unaware of how vital these digital certificates are to the use of the internet. A digital certificate, also called an identity certificate or a public key certificate, is an electronic document that provides a digital signature by which a public key is bound to a specific identity. Secure and accurate knowledge of an identity on the Internet is vital to secure transactions.

A Certificate Authority is the entity that attests to the accuracy of the digital certificates they issue. Hacks against these certificate authorities over the past few months has rendered some digital certificates useless as secure identification schemes.

DigiNotar Logo

DigiNotar, a Dutch Certificate Authority, has recently admitted that they had understated the scope and severity of the hacking which hit them last month. The Dutch government uses some DigiNotar certificates for transactions for university enrollment and tax filing, among other functions, and has banned use of DigiNotar certificates throughout the government's Web sites. Citing problems that may arise with existing transactions, a phased migration to replace digital certificates has begun. Though the Dutch government has not told the public to avoid using the web sites, both courts and lawyers in the Netherlands have advised that any government transactions normally done over the Internet should be done instead by fax or regular mail.

GlobalSign Logo

Microsoft and Google have already implemented a ban of the use of DigiNotar certificates within their respective browsers as indicators of secure web sites; Mozilla has given DigiNotar a deadline of September 15th to improve the situation. Last week, a hacker identifying himself as "Ich Sun" claimed responsibility not only for the DigiNotar attack, but also for earlier attacks on Komodo, an American Internet security company, on StartCom, an Israeli Certificate Authority, and on GlobalSign, a Japanese-owned Certificate Authority.

In response, GlobalSign stopped issuing digital certificates last Tuesday and invited an audit firm to examine its systems for any evidence of hacking. However, on Monday, September 12th, GlobalSign announced that the only evidence discovered within their systems was an access breach of an isolated web server and that they will resume issuing certificates on Tuesday.

The hacker in his announcement, however, had promised at least three more hacking efforts will be done in the new future, implying that more digital certificates may soon be at risk. Web hosting providers and any other company depending on the Internet for business needs should stay aware of the latest developments in this situation.

Add Your Thoughts

  • counterfeit bags
    2012-05-16

    Combating Online Sales of Counterfeit Luxury Products

    A new tactic is being used by fashion companies trying to stop the online sale of counterfeit versions of their trademark luxury products. Up until about ten years, ago, companies like Chanel and Louis Vuitton w...
  • 2012-05-10

    Recent PHP Patching Symptomatic of Larger Problems

    A recent double release of patches by the PHP Group to remedy a vulnerability in Web servers is symptomatic of a problem that those who are responsible for Web servers know all too well. When a vulnerability is ...
  • 2012-05-08

    Shopping Carts for Cyber-Crime

    Last month, government takedowns of criminal websites revealed a disturbing trend: the use of e-commerce to sell illegal data. We've all used online shopping carts and clicked the checkout button on many commerc...
    cyber crime shopping carts
  • obama cispa
    2012-05-03

    CISPA Passed by US House of Representatives

    The Cyber Information Sharing and Protection Act (CISPA) that was passed by the US House of Representatives last week by a vote of 248 to 168 appears to be the next piece of computer-related legislation that wil...
  • automated attacks index
    2012-04-26

    Sophisticated Automated Web Attacks on the Rise

    A recent report on the source and types of application hacking attacks upon Web servers highlights the linked growth of two characteristics, sophistication and automation, for the first few months of 2012. Web a...
  • 2012-04-24

    Australian ISPs and Copyright Infringement

    The war over copyright infringement between Big Media and Internet Service Providers (ISPs) is not confined solely (of course) to the United States and Europe. Recently, a court battle was won by iiNet Limited, ...
    australian isps index
  • emailed bomb threats index
    2012-04-20

    Emailed Bomb Threats in Pittsburgh

    Federal authorities, attempting to trace back three threatening emails that were sent over the last few months to Pennsylvania reporters about bombs supposedly planted at the University of Pittsburgh, found a we...
  • 2012-04-17

    Paying for Megaupload's Servers

    Anyone who played the game of Hot Potato as a child will instantly understand the current situation of the fees for servers involved in the Megaupload case. Last January, the popular file-sharing web site was se...
    dreamhost bills index
  • 2012-04-12

    File Inclusion Attacks Most Prevalent in 2011

    Attacks on web servers by hackers is one of those events most feared by web hosting providers. Besides being categorized by the damage done, these events can also be classified by the type of technique used in t...
  • data cloud expands index
    2012-04-03

    The Data Cloud Expands

    Several trends have started to coalesce recently into a pattern that augurs well for the growth of cloud computing as a service that can be sold to customers who are already purchasing web hosting services. Clou...

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30

Buying Guide

Can't decide what hosting is right for you? Answer 2-5 questions and get your perfect hosting match!

To Questions

User Reviews

Make your voice heard. Review your web hosting provider - good or bad.

  •  
  •  
  •  
  •  
Everything has been very stabile and I was very impressed with all the features and extras that were included in the plan.

Bill about iPage

Read iPage Review

Ask the Editor

Editor

Ask us anything about hosting. We love to help.

David Walsh
editor in chief