Email this article   Print article 


Microsoft Judges DigiNotar SSL Certificates 'Untrustworthy'

By Stefanie Hoffman
September 07, 2011    4:32 PM ET

Page 2 of 2

"The problem for the Dutch online infrastructure is very serious,” Storms said. “I’m sure the Dutch government is learning a hard, but important lesson from this ongoing-fiasco. Trusting DigiNotar’s critical online infrastructure role without spending the time to independently audit their operations has undoubtedly cost the Dutch government a lot of time and money. It has certainly caused a great deal of international embarrassment.”

Meanwhile, DigiNotar doesn’t appear to be the only compromised CA. An Iranian hacker known as ComodoHacker, responsible for SSL hacks against DigiNotar and certificate authority Comodo earlier this year, posted a message on pastebin.com also claiming to have accessed four other CAs, including GlobalSign.

“I still have access to 4 more CAs, I just named one and I re-name it: GlobalSign, StartCom was lucky enough, I already connected to their HSM, got access to their HSM, sent my request, but lucky Eddy (CEO) was sitting behind HSM and was doing manual verification,” ComodoHacker said in the blog post .

The admission compelled the U.K.-based certificate authority GlobalSign to temporarily cease issuing SSL certificates while it launched an investigation. The CA enlisted the help of DigiNotar security auditor Fox-IT to determine the validity of ComodoHacker’s claims and the extent, if any, of the compromise.

“GlobalSign takes this claim very seriously and is currently investigating,” GlobalSign said in a blog post Tuesday. “As a responsible CA, we have decided to temporarily cease issuance of all Certificates until the investigation is complete. We will post updates as frequently as possible. We apologize for any inconvenience.”



<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...