Live data from Hacker News

Diginotar confirms security breach

vasco.com

11–19 of 19 posts

Re: Diginotar confirms security breach

#11
post #10
post #8

"VASCO does not expect that the DigiNotar security incident will have a significant impact on the company’s future revenue or business plans." Anything less than termination of the DigiNotar business and paying for a real third-party equivalent SSL cert of equivalent length for all affected customers who have ever been issued DigiNotar certs, plus compensation for the cost of rekeying, should result in action against…

They're probably right. VASCO's core products and DigiNotar's appear to be separate BUs (they don't even share IT infrastructure according to the press release). And even within DigiNotar, the SSL CA appears to be an afterthought; VASCA says it did less than $100k EU last year. Yes, this does beg the question of why an organization like DigiNotar was allowed to be a browser CA root.

To get a better understanding of how DigiNotar operated, have a look at the Mozilla bug for their CA inclusion: https://bugzilla.mozilla.org/show_bug.cgi?id=369357

Re: Diginotar confirms security breach

#12
http://www.diginotar.nl/Actueel/tabid/264/articleType/Articl...

http://translate.google.com/translate?hl=en&sl=auto&...

Incompetence doesn't begin to describe this statement. They say: Your browser might throw some warnings when communicating with government services. In 99.9% of the cases this is a false alarm and you can safely ignore it.

By own accord 1 in a 1000 (of 9 million users) can get MitM'ed and yet you teach people that it is safe to ignore it... They appear to use the same audit company from last time.

The Consumentbond already tells people to expect warnings and ignore them, for they have not been hacked, but merely experience a temporary "browser issue". Reports of DigiD helpdesk telling people to ignore warnings, lower security settings or place the site in "trusted sites".

Re: Diginotar confirms security breach

#13
This is an Über Failure if I have ever seen one. They detected the breech on July 19th but didn't think to check to see if anything was amiss?!? I think that OS companies and browsers must come down hard on compromised certificate authorities. A ZERO tolerance policy should be enforced resulting in a permanent BAN if your private keys are compromised!

Re: Diginotar confirms security breach

#14

This is even worse: They noticed the breach, and failed to properly identify all certificates issued. I've already removed Diginotar from my Firefox trusted CAs. I don't think they're going to earn their way back in.

They think that by the end of the week they'll be trusted by Microsoft, Google and Mozilla again, they "followed the correct procedures", see http://translate.google.com/translate?hl=en&sl=auto&...

Wow, DigiNotar is insane if they really think that.

The fact that they said that makes me trust them even less.

Re: Diginotar confirms security breach

#15
post #11
post #10

Earlier quoted context omitted.

They're probably right. VASCO's core products and DigiNotar's appear to be separate BUs (they don't even share IT infrastructure according to the press release). And even within DigiNotar, the SSL CA appears to be an afterthought; VASCA says it did less than $100k EU last year. Yes, this does beg the question of why an organization like DigiNotar was allowed to be a browser CA root.

To get a better understanding of how DigiNotar operated, have a look at the Mozilla bug for their CA inclusion: https://bugzilla.mozilla.org/show_bug.cgi?id=369357

I read through this, but I didn't understand enough. It seemed like they were new to this - what did I miss?

Re: Diginotar confirms security breach

#16
post #15
post #11

Earlier quoted context omitted.

To get a better understanding of how DigiNotar operated, have a look at the Mozilla bug for their CA inclusion: https://bugzilla.mozilla.org/show_bug.cgi?id=369357

I read through this, but I didn't understand enough. It seemed like they were new to this - what did I miss?

That it is kind of absurd that the lives of Iranian dissidents depend on this relationship between browser developers and incompetent bid dumb organizations asserting trustworthiness and competence, IMO.

Having lots of CAs is commercial pressure, but as log as any can issue for any, it means security is as vulnerable as the weakest company's weakest system or staffer.

Re: Diginotar confirms security breach

#17
post #16
post #15

Earlier quoted context omitted.

I read through this, but I didn't understand enough. It seemed like they were new to this - what did I miss?

That it is kind of absurd that the lives of Iranian dissidents depend on this relationship between browser developers and incompetent bid dumb organizations asserting trustworthiness and competence, IMO. Having lots of CAs is commercial pressure, but as log as any can issue for any, it means security is as vulnerable as the weakest company's weakest system or staffer.

The lives of Iranian dissidents (a) really don't† and (b) shouldn't depend on browser CA configurations. In reality if your adversary is a hostile government, you should be taking steps beyond verifying SSL certificates.

but not for reasons that will make you happy

Re: Diginotar confirms security breach

#18
post #17
post #16

Earlier quoted context omitted.

That it is kind of absurd that the lives of Iranian dissidents depend on this relationship between browser developers and incompetent bid dumb organizations asserting trustworthiness and competence, IMO. Having lots of CAs is commercial pressure, but as log as any can issue for any, it means security is as vulnerable as the weakest company's weakest system or staffer.

The lives of Iranian dissidents (a) really don't† and (b) shouldn't depend on browser CA configurations. In reality if your adversary is a hostile government, you should be taking steps beyond verifying SSL certificates. † but not for reasons that will make you happy

True, the only reason this happened at all is that unlike most state actors, there are no Iranian CA in the browser roots to directly pressure.

Re: Diginotar confirms security breach

#19

http://www.diginotar.nl/Actueel/tabid/264/articleType/Articl... http://translate.google.com/translate?hl=en&sl=auto&... Incompetence doesn't begin to describe this statement. They say: Your browser might throw some warnings when communicating with government services. In 99.9% of the cases this is a false alarm and you can safely ignore it. By own accord 1 in a 1000 (of 9 million users) can get MitM'ed and yet you te…

> The Consumentbond already tells people to expect warnings and ignore them, for they have not been hacked, but merely experience a temporary "browser issue". Reports of DigiD helpdesk telling people to ignore warnings, lower security settings or place the site in "trusted sites".

Isn't that because Mozilla also blocked certs used by the Dutch gov (which DigiD uses I suppose), which aren't actually compromised?

I read that in a new update they'll unblock the Dutch gov certs though.

Still never a good idea to teach people to ignore warnings, especially not on a site like DigiD.

Post reply on HN