"VASCO does not expect that the DigiNotar security incident will have a significant impact on the company’s future revenue or business plans." Anything less than termination of the DigiNotar business and paying for a real third-party equivalent SSL cert of equivalent length for all affected customers who have ever been issued DigiNotar certs, plus compensation for the cost of rekeying, should result in action against…
They're probably right. VASCO's core products and DigiNotar's appear to be separate BUs (they don't even share IT infrastructure according to the press release). And even within DigiNotar, the SSL CA appears to be an afterthought; VASCA says it did less than $100k EU last year. Yes, this does beg the question of why an organization like DigiNotar was allowed to be a browser CA root.
Diginotar confirms security breach
11–19 of 19 posts
Re: Diginotar confirms security breach
#12http://translate.google.com/translate?hl=en&sl=auto&...
Incompetence doesn't begin to describe this statement. They say: Your browser might throw some warnings when communicating with government services. In 99.9% of the cases this is a false alarm and you can safely ignore it.
By own accord 1 in a 1000 (of 9 million users) can get MitM'ed and yet you teach people that it is safe to ignore it... They appear to use the same audit company from last time.
The Consumentbond already tells people to expect warnings and ignore them, for they have not been hacked, but merely experience a temporary "browser issue". Reports of DigiD helpdesk telling people to ignore warnings, lower security settings or place the site in "trusted sites".
Re: Diginotar confirms security breach
#13Re: Diginotar confirms security breach
#14This is even worse: They noticed the breach, and failed to properly identify all certificates issued. I've already removed Diginotar from my Firefox trusted CAs. I don't think they're going to earn their way back in.
They think that by the end of the week they'll be trusted by Microsoft, Google and Mozilla again, they "followed the correct procedures", see http://translate.google.com/translate?hl=en&sl=auto&...
The fact that they said that makes me trust them even less.
Re: Diginotar confirms security breach
#15Earlier quoted context omitted.
They're probably right. VASCO's core products and DigiNotar's appear to be separate BUs (they don't even share IT infrastructure according to the press release). And even within DigiNotar, the SSL CA appears to be an afterthought; VASCA says it did less than $100k EU last year. Yes, this does beg the question of why an organization like DigiNotar was allowed to be a browser CA root.
To get a better understanding of how DigiNotar operated, have a look at the Mozilla bug for their CA inclusion: https://bugzilla.mozilla.org/show_bug.cgi?id=369357
Re: Diginotar confirms security breach
#16Earlier quoted context omitted.
To get a better understanding of how DigiNotar operated, have a look at the Mozilla bug for their CA inclusion: https://bugzilla.mozilla.org/show_bug.cgi?id=369357
I read through this, but I didn't understand enough. It seemed like they were new to this - what did I miss?
Having lots of CAs is commercial pressure, but as log as any can issue for any, it means security is as vulnerable as the weakest company's weakest system or staffer.
Re: Diginotar confirms security breach
#17Earlier quoted context omitted.
I read through this, but I didn't understand enough. It seemed like they were new to this - what did I miss?
That it is kind of absurd that the lives of Iranian dissidents depend on this relationship between browser developers and incompetent bid dumb organizations asserting trustworthiness and competence, IMO. Having lots of CAs is commercial pressure, but as log as any can issue for any, it means security is as vulnerable as the weakest company's weakest system or staffer.
† but not for reasons that will make you happy
Re: Diginotar confirms security breach
#18Earlier quoted context omitted.
That it is kind of absurd that the lives of Iranian dissidents depend on this relationship between browser developers and incompetent bid dumb organizations asserting trustworthiness and competence, IMO. Having lots of CAs is commercial pressure, but as log as any can issue for any, it means security is as vulnerable as the weakest company's weakest system or staffer.
The lives of Iranian dissidents (a) really don't† and (b) shouldn't depend on browser CA configurations. In reality if your adversary is a hostile government, you should be taking steps beyond verifying SSL certificates. † but not for reasons that will make you happy
Re: Diginotar confirms security breach
#19http://www.diginotar.nl/Actueel/tabid/264/articleType/Articl... http://translate.google.com/translate?hl=en&sl=auto&... Incompetence doesn't begin to describe this statement. They say: Your browser might throw some warnings when communicating with government services. In 99.9% of the cases this is a false alarm and you can safely ignore it. By own accord 1 in a 1000 (of 9 million users) can get MitM'ed and yet you te…
Isn't that because Mozilla also blocked certs used by the Dutch gov (which DigiD uses I suppose), which aren't actually compromised?
I read that in a new update they'll unblock the Dutch gov certs though.
Still never a good idea to teach people to ignore warnings, especially not on a site like DigiD.