Diginotar confirms security breach
vasco.com
Diginotar confirms security breach
1–10 of 19 posts
Re: Diginotar confirms security breach
#2Re: Diginotar confirms security breach
#3[deleted]
Re: Diginotar confirms security breach
#4I've already removed Diginotar from my Firefox trusted CAs. I don't think they're going to earn their way back in.
Re: Diginotar confirms security breach
#5Re: Diginotar confirms security breach
#6This is even worse: They noticed the breach, and failed to properly identify all certificates issued. I've already removed Diginotar from my Firefox trusted CAs. I don't think they're going to earn their way back in.
Re: Diginotar confirms security breach
#7There's some interesting additional commentary on the F-Secure Blog ( http://www.f-secure.com/weblog/archives/00002228.html ). Looks like they'd been breached multiple times.
What can you do with such a certificate? Well, you can impersonate Google -- assuming you can first reroute Internet traffic for google.com to you. This is something that can be done by a government or by a rogue ISP. Such a reroute would only affect users within that country or under that ISP.
This is not entirely true...
For a short time on Tuesday, internet traffic sent between Facebook and subscribers to AT&T's internet service passed through hardware belonging to the state-owned China Telecom before reaching its final destination
-- http://www.theregister.co.uk/2011/03/23/facebook_traffic_chi...
Re: Diginotar confirms security breach
#8Anything less than termination of the DigiNotar business and paying for a real third-party equivalent SSL cert of equivalent length for all affected customers who have ever been issued DigiNotar certs, plus compensation for the cost of rekeying, should result in action against VASCO (the parent company). It's obvious they don't take the SSL cert business seriously, and it's a small part of their revenue, so they need to just exit it.
Re: Diginotar confirms security breach
#9There's some interesting additional commentary on the F-Secure Blog ( http://www.f-secure.com/weblog/archives/00002228.html ). Looks like they'd been breached multiple times.
From that blog post... What can you do with such a certificate? Well, you can impersonate Google -- assuming you can first reroute Internet traffic for google.com to you. This is something that can be done by a government or by a rogue ISP. Such a reroute would only affect users within that country or under that ISP. This is not entirely true... For a short time on Tuesday, internet traffic sent between Facebook and…
Also, any entity trusted only to receive traffic but not to route third-party traffic will typically get limited to routes that lead to its own IP block, making this only an option for entities trusted to actually route third-party traffic. And if any such entity pulled a stunt like this more than once, they'd have a hard time arguing that it occurred accidentally.
Re: Diginotar confirms security breach
#10"VASCO does not expect that the DigiNotar security incident will have a significant impact on the company’s future revenue or business plans." Anything less than termination of the DigiNotar business and paying for a real third-party equivalent SSL cert of equivalent length for all affected customers who have ever been issued DigiNotar certs, plus compensation for the cost of rekeying, should result in action against…
Yes, this does beg the question of why an organization like DigiNotar was allowed to be a browser CA root.