2012-06-30

SSL Certificates Stolen From DigiNotar

Approximately 531 certificates were stolen, possibly by the Iranian Government.

Technet has a very good article around why such an attack is brutal and how to protect against it

Microsoft feels this could even lead to attackers pushing malware via Windows automatic update



Impact of this hack:

Update 07-Sep-11:
        Not surprisingly, the same hacker which attacked Comodo, has taken the responsibility of this hack
        To make matters worse, he claims to have compromised four other Certificate Authorities (CA)..!!

Update 09-Sep-11:
        Fox-IT has published a very good report on the incident

        ComodoHacker claims he can now exploit Windows Update as well

Update 12-Sep-11:

Update 27-Sep-11:
        DigiNotar has filled for bankruptcy, plus the Dutch government has revoked their root cert

Update 28-Jun-12:
        Dutch govt tells us how difficult & time consuming it is to replace all digital certs in an organization.

Update 01-Nov-12:
Fox IT now details the attack


No comments:

Post a Comment