Man-in-the-middle attack on Github. -- http://bit.ly/Vqh8zJ
Fake GITHUB cert -- http://www.mediafire.com/?zx6eno648axz7bh
Twitter (Github attack news) -- https://www.twitter.com/search/?q=Github%20SSL
1–10 of 78 posts
Man-in-the-middle attack on Github. -- http://bit.ly/Vqh8zJ
Fake GITHUB cert -- http://www.mediafire.com/?zx6eno648axz7bh
Twitter (Github attack news) -- https://www.twitter.com/search/?q=Github%20SSL
Still, shows the depth and corruption the China (gov't).
Read the Twitter stream - affects people inside China. Still, shows the depth and corruption the China (gov't). https://twitter.com/search/?q=Github%20SSL
If they put this fake certificate in a certificate root server that's in the trusted server list, they can easily get anyone's account who's using affected browsers.
It's weird that they start with Github. It's not a website that's popular among human activists or any other people that China government might be interested in. Instead, it's popular among programmers and hackers, who are the main group and forces in China to help people bypass GFW to access blocked content. I suppose this attack might be what the government uses to test reaction and capability of hackers.
Seriously, this is really, really, bad.
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=542689
EDIT: added link for bug report
How would this fake cert work? It doesn't seem to originate with a root or have any associated information. Do browsers actually accept certs that look like this?
This reminds me the Firefox certificate "bug"[1] two years ago. A China certificate root server was added into trusted servers in Firefox and Chinese hackers started to submit bug report regarding this, since people don't trust certificate servers run by China government. Man-in-the-middle attack was exact what Chinese hackers worried about. If they put this fake certificate in a certificate root server that's in the…
RT @chenshaoju 无锡电信实际测试GitHub已经遭到SSL中间人攻击。 http://bit.ly/X49oPK
This reminds me the Firefox certificate "bug"[1] two years ago. A China certificate root server was added into trusted servers in Firefox and Chinese hackers started to submit bug report regarding this, since people don't trust certificate servers run by China government. Man-in-the-middle attack was exact what Chinese hackers worried about. If they put this fake certificate in a certificate root server that's in the…
If you actually look at the certificate, it is self-signed, not signed by a malicious root server. Your anecdote has nothing to do with this current attack.
(We ended up setting up a gitlab box and it works just as well)