Live data from Hacker News

Diginotar confirms security breach

vasco.com

1–10 of 19 posts

Re: Diginotar confirms security breach

#6

This is even worse: They noticed the breach, and failed to properly identify all certificates issued. I've already removed Diginotar from my Firefox trusted CAs. I don't think they're going to earn their way back in.

They think that by the end of the week they'll be trusted by Microsoft, Google and Mozilla again, they "followed the correct procedures", see http://translate.google.com/translate?hl=en&sl=auto&...

Re: Diginotar confirms security breach

#7

There's some interesting additional commentary on the F-Secure Blog ( http://www.f-secure.com/weblog/archives/00002228.html ). Looks like they'd been breached multiple times.

From that blog post...

What can you do with such a certificate? Well, you can impersonate Google -- assuming you can first reroute Internet traffic for google.com to you. This is something that can be done by a government or by a rogue ISP. Such a reroute would only affect users within that country or under that ISP.

This is not entirely true...

For a short time on Tuesday, internet traffic sent between Facebook and subscribers to AT&T's internet service passed through hardware belonging to the state-owned China Telecom before reaching its final destination

-- http://www.theregister.co.uk/2011/03/23/facebook_traffic_chi...

Re: Diginotar confirms security breach

#8
"VASCO does not expect that the DigiNotar security incident will have a significant impact on the company’s future revenue or business plans."

Anything less than termination of the DigiNotar business and paying for a real third-party equivalent SSL cert of equivalent length for all affected customers who have ever been issued DigiNotar certs, plus compensation for the cost of rekeying, should result in action against VASCO (the parent company). It's obvious they don't take the SSL cert business seriously, and it's a small part of their revenue, so they need to just exit it.

Re: Diginotar confirms security breach

#9
post #7

There's some interesting additional commentary on the F-Secure Blog ( http://www.f-secure.com/weblog/archives/00002228.html ). Looks like they'd been breached multiple times.

From that blog post... What can you do with such a certificate? Well, you can impersonate Google -- assuming you can first reroute Internet traffic for google.com to you. This is something that can be done by a government or by a rogue ISP. Such a reroute would only affect users within that country or under that ISP. This is not entirely true... For a short time on Tuesday, internet traffic sent between Facebook and…

Any ISP or country which sent bogus routes like that would get away with it briefly, before getting blackholed. So, sure, if you just needed a window of a couple of minutes and you didn't mind it making international news, you could do this.

Also, any entity trusted only to receive traffic but not to route third-party traffic will typically get limited to routes that lead to its own IP block, making this only an option for entities trusted to actually route third-party traffic. And if any such entity pulled a stunt like this more than once, they'd have a hard time arguing that it occurred accidentally.

Re: Diginotar confirms security breach

#10
post #8

"VASCO does not expect that the DigiNotar security incident will have a significant impact on the company’s future revenue or business plans." Anything less than termination of the DigiNotar business and paying for a real third-party equivalent SSL cert of equivalent length for all affected customers who have ever been issued DigiNotar certs, plus compensation for the cost of rekeying, should result in action against…

They're probably right. VASCO's core products and DigiNotar's appear to be separate BUs (they don't even share IT infrastructure according to the press release). And even within DigiNotar, the SSL CA appears to be an afterthought; VASCA says it did less than $100k EU last year.

Yes, this does beg the question of why an organization like DigiNotar was allowed to be a browser CA root.

Post reply on HN