Subscribe:
Showing posts with label Comodo. Show all posts
Showing posts with label Comodo. Show all posts

Thursday, 1 September 2011

Breaches Raise Questions about SSL Security


The recent breach at Dutch digital certificate authority DigiNotar is just the latest in series of troubling SSL hacks. Earlier this year, Comodo alerted its customers to a serious SSL breach that impacted nine Web domains, including Google and Yahoo. Now with details emerging about the attack on DigiNotar’s SSL and EV-SSL CA system, we think it’s time to take a closer look at SSL security.

In fact, in July NCP engineering* released a whitepaper “Debunking the Myths of SSL VPN Security,” taking on this very topic. So using this whitepaper as a guide, VPN Haus is launching a multi-part series that the asks questions: why do so many high profile breaches occur using SSL VPN? Do users simply not implement the technology correctly? Or does SSL fall short of the marketing hype? We’ll dig for these answers by exploring the following SSL VPN myths:

Myth 1: Using trusted certificates from a certificate authority (CA) is airtight.
Myth 2:  SSL VPN is clientless.
Myth 3: Online banking via SSL session is secure.
Myth 4: HTTPS is a secure pipe.
Myth 5: One-way certificate authentication of a SOA web service is secure because it uses HTTPS.
Myth 6: Two-way certificate exchange between a SOA web service and a client can always be trusted.
Myth 7: Java Authentication and Authorization Services (JAAS) framework handles all protocols and mechanisms in a secure manner.
Myth 8: RSA SecurID provides a secure connection.
Myth 9: Thick-client SSL VPNs are more secure than thin-client SSL VPNs.
Myth 10: Security is the responsibility of a specialist department.

Moreover, Myth 1 deals head-on with issue Comodo, and now DigiNortar, faced with its fraudulent certificates. We’ll go more into that next week. But for now, we invite you to weigh in with your thoughts as we take a deep dive into the murky waters of SSL, in hopes of eliminating confusion, providing greater clarity, and ultimately, peace-of-mind on SSL and security.

Tuesday, 30 August 2011

Stolen Google Certificate Puts Gmail Accounts in Danger

Hackers obtained a Google.com authentication certificate. Credit: Google

Hackers have obtained a Google website authentication certificate, putting anyone visiting a Google-owned Web property, including Gmail and YouTube, in serious danger.

The Secure Sockets Layer (SSL) certificate allows whoever is wielding it to set up fraudulent Web pages under a legitimate Google domain name; the victims, security researchers say, would believe they were on a perfectly safe Google site while, behind the scenes, attackers could harvest all their personal information.

"This type of attack allows someone to eavesdrop on encrypted traffic, allowing them to decipher traffic which would otherwise not be possible," Kaspersky Lab researcher Roel Schouwenberg told SecurityNewsDaily.

Why is this so scary?

Most phishing emails or spoofed websites look legitimate, but close inspection will reveal a misspelled URL an unencrypted Web session, or a third-party Web page that bears no resemblance to the original address. Anti-virus software often will detect these rogue pages as threats before they even get to you.
A stolen SSL certificate, however, could mean that when you log on to your Gmail account, or receive an email with a link to any Google.com Web domain (a YouTube video, for example), all of your credentials could be up for grabs.

"This particular certificate is a so-called 'wildcard' certificate," Schouwenberg said. "It's valid for any google.com subdomain. This means this certificate allows an attacker to eavesdrop on virtually all of Google's services, including Gmail, while the traffic is encrypted. This will allow the attacker to not only read/write emails but also grab the target's Google credentials."

Even worse, your computer — and you — would never even know, because nothing about the site would seem off. After all, the attack could take place on an encrypted Gmail page.

How did it happen?

Hackers accessed the SSL certificate on July 19 from DigiNotar, a Dutch certificate authority, which said in apress release that the breach "resulted in the fraudulent issuance of public key certificate requests for a number of domains, including Google.com."

DigiNotar said it revoked all the fraudulently issued certificates, but "recently, it was discovered that at least one fraudulent certificate had not been revoked at the time."

That certificate, for Google.com, has since been revoked, but it existed in the wild for more than five weeks.

An email to DigiNotar was not returned.

Who is behind the hack?

"This type of attack is mostly suited to intelligence/espionage operations," Schouwenberg said. "We have to keep in mind that these attacks are quite targeted and most likely carried out by nation-states."

Mikko Hypponen from the security firm F-Secure captured a screenshot of a compromised DigiNotar Web page that reads, "Hacked by KiAnPhP, Extrance Digital Security Team, Iranian Hackers."

"It's likely the Government of Iran is using these techniques to monitor local dissidents," Hypponen wrote.
Google itself supports this claim, writing in a blog post on Sunday (Aug. 28) that "the people affected were primarily located in Iran."

However, Hypponen came across another defaced DigiNotar Web page that reads, "Hacked by Black.Spook! Persian Gulf For Ever!!!"

"If you keep digging deeper, you'll find that although these Web defacements are still live right now, they are not new," Hypponen wrote. "Much worse: They were done years ago. In fact, these hacks are so old, it's unlikely they are connected to the current problem. Or at least so we hope."

What can you do?

"Unfortunately, there are only very few solutions for this type of problem," Schouwenberg told SecurityNewsDaily. "Right now, we have to rely on the browser makers to release an update to the browser which blacklists this particular certificate."

Thankfully, Mozilla Firefox, Microsoft Internet Explorer and Google Chrome have all updated their Web browsers to block the stolen Google SSL certificate.

Google warns users, especially located in Iran, to "keep their Web browsers and operating systems up to date and pay attention to Web browser security warnings."

Attackers Obtain Valid Cert for Google Domains, Mozilla Moves to Revoke It


A certificate authority in the Netherlands issued a valid SSL wildcard certificate for Google to a third party in July, leading to concerns that attackers may have been using the certificate to route sensitive traffic through their own servers, capturing it and compromising user data in the process. The certificate was revoked by the CA, DigiNotar, after the problem came to light Monday.

The attack appears to have been targeting Gmail users specifically. Some users trying to reach the Gmail servers over HTTPS found that their traffic was being rerouted through servers that shouldn't have been part of the equation. On Monday afternoon, security researcher Moxie Marlinspike checked the signatures on the certificate for the suspicious server, which had been posted to Pastebin and elsewhere on the Web, and found that the certificate was in fact valid. The attack is especially problematic because the certificate is a wildcard cert, meaning it is valid for any of Google's domains that use SSL.

It's not clear who DigiNotar issued the certificate to at this point.

Security and privacy experts began discussing the problem Monday, after some people in Iran began posting messages to Twitter and elsewhere about the possibility of a man-in-the-middle attack by the country's government, using the certificate. The certificate was issued on July 10, and Mozilla said on Monday that it is planning to isue immediate updates to many of its products, including Firefox, Thunderbird and others, to remove the DigiNotar root CA.

"Users on a compromised network could be directed to sites using a fraudulent certificate and mistake them for the legitimate sites. This could deceive them into revealing personal information such as usernames and passwords. It may also deceive users into downloading malware if they believe it’s coming from a trusted site. We have received reports of these certificates being used in the wild," Mozilla securityofficials said in a blog post.

"Because the extent of the mis-issuance is not clear, we are releasing new versions of Firefox for desktop (3.6.21, 6.0.1, 7, 8, and 9) and mobile (6.0.1, 7, 8, and 9), Thunderbird (3.1.13, and 6.0.1) and SeaMonkey (2.3.2) shortly that will revoke trust in the DigiNotar root and protect users from this attack."
The problem with the fraudulent *.google.com certificate is quite similar to the results of the attack on Comodo earlier this year in which the attackers were able to compromise one of the company's European registration authorities and issue valid SSL certs for Gmail, Yahoo, Skype and several other high-value sites.

Firefox users who want to disable the browser's trust of the DigiNotar root immediately can do so by clicking on Options, then Advanced, then Encryption and then selecting the View Certificates option. Then scroll down to the DigiNotar root CA, click on it and then click on Delete or Distrust.

Monday, 27 June 2011

ComodoSSLStore.com Offers Guaranteed Cheapest SSL Certificates Starting @ $6.50/Year

ComodoSSLstore.com revised their pricing to offer the lowest price. Visit Comodo SSL Store to buy SSL certificates at an affordable price, starting @ $6.50/year.


Online PR News – 22-June-2011 –St. Petersburg, FL - ComodoSSLstore.com is an authorized Platinum Partner of Comodo, one of the leading SSL Certificate Authority (CA) organizations, reselling SSL Certificates from the global leader in security at the world’s most discounted prices.


ComodoSSLstore.com is a leading provider of authentication and encryption for Web sites, enhancing online credibility through its broad catalog of Comodo SSL certificates. The site recently improved its SSL product offerings. Comodo SSL Store offers a low-price guarantee (the Price Match program) and provides the best support team: 24/7 by email, live chat and phone.

ComodoSSLstore.com offer Comodo SSL Certificate at a very reasonable price compared to Comodo (CA) and all other Comodo SSL certificate resellers worldwide. Comodo SSL Store believes in the pursuit of e-commerce and enterprise security and online confidence at the lowest price. The company buys in bulk and passes on the savings to its customers.

Equipped with a full spectrum of SSL certificate options, ComodoSSLstore.com offers world-class SSL Certificates with a fast turnaround at an affordable price. Comodo SSL Certificates support 128/256 bit encryption levels and are signed with 2048-bit algorithms in accordance with United States NIST recommendations (nist.gov).

ComodoSSLstore.com

Comodo SSL Certificates

ComodoSSLstore.com offers less expensive SSL certificate for e-business security. Buy or renew Comodo SSL Certificate as low as $6.50/year. The certificate is available on the Internet at an affordable price. For bids on bulk purchasing, visit https://comodosslstore.com/ and contact support. We will either help you immediately, or if needed, a Business Development Manager will contact you.

SSL Price Match

Simply email us the link where you found the cheaper price and we will get back to you with a coupon code to match or beat it. You can also chat through our website and get a coupon code that way.

Why ComodoSSLStore?

• 24/7 Support: We work around the clock to serve you better and answer questions whenever you need us night or day. Our experienced technical support staff will guide you through your SSL purchase and installation.

• Product Selection: We’re a Platinum Partner for Comodo and carry over 20 different types of SSL certificates. You can always find the perfect one to meet your needs.

• Competitive Pricing: We monitor SSL certificate pricing very closely and adjust our prices accordingly by further negotiating better pricing with Comodo. If you find it anywhere else cheaper, let us know and we will match or beat their price.

• Best Partner Program: We have designed the best partner program in the SSL industry. We reward our loyal customers with cheaper SSL prices. The more you buy the lower your price, and it never expires. We track all your purchases, and as soon as you reach the next level, your prices change automatically. Better yet, switch to us from any other competitor; show us your previous purchases, and we will start you from that level automatically.

Based in St. Petersburg, Florida, ComodoSSLStore.com is one of the largest global providers of Comodo SSL certificates. As a platinum partner for Comodo, we offer the lowest Comodo prices available, guaranteed. We buy SSL certificates in large quantities and pass the savings on to you. To learn more about Comodo SSL Certificates, visit https://comodosslstore.com/, where you can get your SSL Security Certificate and enroll in our $10,000 warranty program.