Subscribe:
Showing posts with label SSL. Show all posts
Showing posts with label SSL. Show all posts

Sunday, 11 September 2011

Apple revokes DigitNotar certs, Mozilla asks CAs to audit

Apple is the last of the major web browser makers to revoke certificates issued by embattled Dutch-based certificate authority DigiNotar.

In a security advisory released Friday, the Cupertino, Calif.-based computing giant updated Mac OS X 10.6.8 and 10.7.1 to remove DigiNotar from its list of trusted root and extended-validation (EV) SSL certificates. In addition, the patch from Apple configures the Mac platform's default system settings to not trust DigiNotar certificates issued by DigiNotar or any of its partners.

Apple did not, however, release updates for iOS, which powers its iPad and iPhone devices.
Microsoft, Mozilla, Google and Opera already have released updates revoking the DigiNotar certs.
Meanwhile, Adobe said Thursday that it was "in the process of removing the DigiNotar Qualified CA certificate from the Adobe Approved Trust List (AATL)."

And Mozilla, maker of the Firefox browser, is asking all CAs that participate in its root program to audit its PKI infrastructure and systems "to check for intrusion or compromise." In addition, the request, sent Thursday from Kathleen Wilson, owner of Mozilla's CA Certificates Module, asks respondents to ensure that multifactor authentication is in place for all accounts that can issue certificates, as well as confirming that other security controls are deployed.

"Participation in Mozilla's root program is at our sole discretion, and we will take whatever steps are necessary to keep our users safe," the note said. "Nevertheless, we believe that the best approach to safeguard that security is to work with CAs as partners, to foster open and frank communication, and to be diligent in looking for ways to improve."

CAs DigiNotar, which is owned by U.S.-based VASCO, and Jersey City, N.J.-based Comodo have fallen victim this year to hacker attacks. The breaches have resulted in the issuance of counterfeit certificates for such high-profile websites as Google.

Almost all of the victims in both incidents appear to live in Iran.

Thursday, 1 September 2011

Breaches Raise Questions about SSL Security


The recent breach at Dutch digital certificate authority DigiNotar is just the latest in series of troubling SSL hacks. Earlier this year, Comodo alerted its customers to a serious SSL breach that impacted nine Web domains, including Google and Yahoo. Now with details emerging about the attack on DigiNotar’s SSL and EV-SSL CA system, we think it’s time to take a closer look at SSL security.

In fact, in July NCP engineering* released a whitepaper “Debunking the Myths of SSL VPN Security,” taking on this very topic. So using this whitepaper as a guide, VPN Haus is launching a multi-part series that the asks questions: why do so many high profile breaches occur using SSL VPN? Do users simply not implement the technology correctly? Or does SSL fall short of the marketing hype? We’ll dig for these answers by exploring the following SSL VPN myths:

Myth 1: Using trusted certificates from a certificate authority (CA) is airtight.
Myth 2:  SSL VPN is clientless.
Myth 3: Online banking via SSL session is secure.
Myth 4: HTTPS is a secure pipe.
Myth 5: One-way certificate authentication of a SOA web service is secure because it uses HTTPS.
Myth 6: Two-way certificate exchange between a SOA web service and a client can always be trusted.
Myth 7: Java Authentication and Authorization Services (JAAS) framework handles all protocols and mechanisms in a secure manner.
Myth 8: RSA SecurID provides a secure connection.
Myth 9: Thick-client SSL VPNs are more secure than thin-client SSL VPNs.
Myth 10: Security is the responsibility of a specialist department.

Moreover, Myth 1 deals head-on with issue Comodo, and now DigiNortar, faced with its fraudulent certificates. We’ll go more into that next week. But for now, we invite you to weigh in with your thoughts as we take a deep dive into the murky waters of SSL, in hopes of eliminating confusion, providing greater clarity, and ultimately, peace-of-mind on SSL and security.

Tuesday, 30 August 2011

Attackers Obtain Valid Cert for Google Domains, Mozilla Moves to Revoke It


A certificate authority in the Netherlands issued a valid SSL wildcard certificate for Google to a third party in July, leading to concerns that attackers may have been using the certificate to route sensitive traffic through their own servers, capturing it and compromising user data in the process. The certificate was revoked by the CA, DigiNotar, after the problem came to light Monday.

The attack appears to have been targeting Gmail users specifically. Some users trying to reach the Gmail servers over HTTPS found that their traffic was being rerouted through servers that shouldn't have been part of the equation. On Monday afternoon, security researcher Moxie Marlinspike checked the signatures on the certificate for the suspicious server, which had been posted to Pastebin and elsewhere on the Web, and found that the certificate was in fact valid. The attack is especially problematic because the certificate is a wildcard cert, meaning it is valid for any of Google's domains that use SSL.

It's not clear who DigiNotar issued the certificate to at this point.

Security and privacy experts began discussing the problem Monday, after some people in Iran began posting messages to Twitter and elsewhere about the possibility of a man-in-the-middle attack by the country's government, using the certificate. The certificate was issued on July 10, and Mozilla said on Monday that it is planning to isue immediate updates to many of its products, including Firefox, Thunderbird and others, to remove the DigiNotar root CA.

"Users on a compromised network could be directed to sites using a fraudulent certificate and mistake them for the legitimate sites. This could deceive them into revealing personal information such as usernames and passwords. It may also deceive users into downloading malware if they believe it’s coming from a trusted site. We have received reports of these certificates being used in the wild," Mozilla securityofficials said in a blog post.

"Because the extent of the mis-issuance is not clear, we are releasing new versions of Firefox for desktop (3.6.21, 6.0.1, 7, 8, and 9) and mobile (6.0.1, 7, 8, and 9), Thunderbird (3.1.13, and 6.0.1) and SeaMonkey (2.3.2) shortly that will revoke trust in the DigiNotar root and protect users from this attack."
The problem with the fraudulent *.google.com certificate is quite similar to the results of the attack on Comodo earlier this year in which the attackers were able to compromise one of the company's European registration authorities and issue valid SSL certs for Gmail, Yahoo, Skype and several other high-value sites.

Firefox users who want to disable the browser's trust of the DigiNotar root immediately can do so by clicking on Options, then Advanced, then Encryption and then selecting the View Certificates option. Then scroll down to the DigiNotar root CA, click on it and then click on Delete or Distrust.

Thursday, 25 August 2011

Symantec Shows Largest Growth in SSL Certificates for August and Continues to Lead Critical EV SSL Market

MOUNTAIN VIEW, Calif. – August 24, 2011 – Symantec Corp. (Nasdaq: SYMC) today announced that it achieved the largest overall SSL certificate growth in the market for August, with a gain of 19,892 total certificates for the month. Symantec remains the market share leader among all SSL certificate authorities worldwide. Symantec also demonstrated leadership in the growing extended validation (EV) SSL market, which grew overall to more than 47,000 certificates.

Extended Validation growth


Symantec was responsible for most (1,752) of this month's overall growth of 2,725 EV certificates, helping to increase the total to 47,532. Netcraft reported that Symantec leads the space with a market share of 68 percent, further demonstrating that when it comes to web security, the majority of organizations online rely on Symantec.


When a website is protected with an EV SSL Certificate, the latest high-security browsers show prominent visual cues to signal that the site has been authenticated to a higher level. For instance, Internet Explorer as well as Firefox browsers display a green address bar and a field with the name of the organization that owns the website. Both are instantly recognizable signals to consumers that they have reached a website whose identity has been certified by a recognized SSL certificate authority such as Symantec.

“The Netcraft Survey data for August clearly demonstrates that EV SSL is a growing business and that Symantec is leading the charge,” said Fran Rosch, vice president of Trust Services at Symantec. “Customers continually realize the value of working with a trusted certificate authority for SSL and EV SSL and view Symantec as a trusted partner as we continue our innovation and leadership to provide the most comprehensive product lineup and highest standards in technical support.”
Related





Connect with Symantec








About Business Solutions from Symantec



Symantec helps organizations secure and manage their information-driven world with endpoint security, messaging security, web security,data protection, identity validation and authentication, and security management solutions.


About Symantec


Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.


Note to Editors: If you would like additional information on Symantec Corporation and its products, please visit the Symantec News Room athttp://www.symantec.com/news. All prices noted are in U.S. dollars and are valid only in the United States.

Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners.