Email this article   Print article 

VeriSign's Gaffe Spurs Debate

By Marcia Savage, CRN
March 30, 2001    4:23 PM ET

Solution providers are divided about the future of VeriSign and the role of digital certificates after the security company revealed it mistakenly issued digital certificates to someone posing as a Microsoft employee.

"VeriSign lost a lot of credibility on the trust dimension because of this," says Larry Ponemon, president of security services firm Guardent, Waltham, Mass. "The digital certificate could fall out of favor as a tool of authentication."

But Jeff Johnson, chairman and chief strategy officer at Metases, an Atlanta-based security services firm, says people will soon forget the incident.

VeriSign, Mountain View, Calif., disclosed in late March that it issued two digital certificates in January to an individual posing as a Microsoft representative. The certificates, which the company has since revoked, could have allowed the imposter to create code that appears to come from Microsoft but is destructive.

Human error led to the issue of the false certificates, VeriSign says. The company says it is adding more manual checks and balances to prevent such events in the future.

The incident drives home the nontechnical aspect of information security, says Wayne Pierce, director of service development, Athena Security, a Cambridge, Mass.-based solution provider. The imposter obtained Microsoft certificates through a more traditional form of fraud, not by hacking. "The technology could be perfectly fine, but they didn't look at the people side of it," he says.

VeriSign's honesty about its mistake should help prevent backlash against the use of digital certificates, Pierce says, adding that it's hard to tell how big of a security risk the use of false certificates poses.

Still, concern about the incident may open the door for other forms of digital identity authentication.


Email this article   Print article 

More Channel Programs

Recent Articles

Five Companies That Dropped The Ball This Week

For the week ending Feb. 10, CRN looks at five companies that were either asleep at the wheel or just didn't make good decisions.

Five Companies That Came To Win This Week

For the week ending Feb. 10, CRN looks at five companies that brought their 'A' game and made moves to beat out competitors

10 Challenges That HP Wants Partners To Tackle Right Now

CRN speaks with HP's business unit chiefs to get a sense of where they'd like partners to focus in the coming year, as well as how CEO Meg Whitman is making a difference.

  More Slide Shows




Related Videos
Loading...