Subscribe:
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Wednesday, 7 September 2011

Century Payments Partners with Trustwave to Offer Merchants PCI Compliance Solutions



Century Payments, today selected Trustwave to provide Payment Card Industry Data Security Standard (PCI  DSS) compliance validation solutions to its Level 4 merchants. Trustwave is a leading provider of information security and compliance solutions.

The PCI DSS is the payment card industry security requirement for entities that store, process or transmit cardholder data, and has been endorsed by all the major card brands - Visa, MasterCard Worldwide, Discover Network, American Express and JCB.

In an effort to assist merchants with their compliance efforts, Century engaged Trustwave to provide its merchants access to TrustKeeper®, Trustwave's innovative security and compliance web portal.

Trustwave's TrustKeeper is a revolutionary web portal that supports merchants' compliance efforts, including moving merchants through the complex compliance process with greater ease and efficiency by making the tasks achievable by non-technical users. This helps facilitate PCI DSS compliance validation for merchants or acquirers, ISOs and processors with large merchant populations.

TrustKeeper features PCI Wizard, which simplifies the complex PCI DSS compliance process. Additionally, TrustKeeper Agent helps merchants identify if unencrypted cardholder data or track data is stored, thereby reducing the merchants' risk of card data theft. TrustKeeper also helps merchants complete required vulnerability scans and receive their PCI DSS compliance certificate.

"After careful consideration of other programs, we chose Trustwave because they most aligned with our goals and objectives around data security for our merchant portfolio," said Christopher Justice, president of Century Payments. "Trustwave's industry expertise and merchant compliance program will help our clients validate and maintain their PCI DSS compliance through easy-to-complete steps that any-sized merchant can understand."

"Trustwave is excited to partner with Century Payments, a leading payment processor, because they understand the importance of validating PCI DSS compliance across their merchant portfolio and are ready to provide the resources necessary to help manage the requirements," said Robert J. McCullen, chairman, CEO and president of Trustwave. "Our merchant compliance program provides Century Payments the necessary tools to help lead their merchants through the compliance process in a step-by-step program that translates the difficult tasks of compliance validation into a comprehensible language for merchants of any size."

About Century Payments
Century Payments, Inc. (centurypayments.com) is a nationally recognized leader in the electronic payment processing industry, dedicated to developing the most progressive, dynamic programs to benefit merchants, partners and agents alike. Through white label alliance programs, Century is the fastest growing electronic payments company having boarded over 50,000 merchants in the last three years and processing close to $10 billion in annual volume. In 2011, Century entered into an elite group recognized on the Inc. 500 list as one of the top 20 fastest growing, privately owned businesses for two consecutive years. The company is headquartered in Frisco, Texas.

About Trustwave
Trustwave (
trustwave.com) is a leading provider of on-demand and subscription-based information security and payment card industry compliance management solutions to businesses and government entities throughout the world. For organizations faced with today's challenging data security and compliance environment, Trustwave provides a unique approach with comprehensive solutions that include its flagship TrustKeeper PCI Compliance management software and other proprietary security solutions including SIEM, EV SSL certificates and secure digital certificates. Trustwave has helped hundreds  of thousands of organizations-ranging from Fortune 500 businesses and large financial institutions to small and medium-sized retailers-manage compliance and secure their network infrastructures, data communications and critical information assets. Trustwave is headquartered in Chicago with offices throughout North America, South America, Europe, Africa, Asia and Australia.


Tuesday, 30 August 2011

Digital Certificate Authority Hacked, Dozens Of Phony Digital Certificates Issued


DigiNotar confirms it was breached and Google.com just one of 'several dozens' of fraudulently issued digital certificates obtained by hackers and now revoked
By Kelly Jackson Higgins
Dark Reading
 

What at first appeared to be a one-off attack targeting Google Gmail users was actually part of a larger breach at Dutch digital certificate authority (CA) DigiNotar, which today confirmed speculation that it indeed was hacked and its SSL and EV SSL CA system abused by attackers.

"The company found out on July 19 that a hacking attempt had happened. At that moment, DigiNotar ordered an external security audit. This audit concluded that all fraudulently issued certificates were revoked. We found out yesterday, through [Dutch government organization] Govcert, that the Google certificate was active. We revoked it immediately," said a spokesman today at Vasco Data Security International, of which the Dutch DigiNotar is a wholly owned subsidiary. He declined to name the other compromised domains, whose phony certs were revoked, but said there were "several dozens of SSL Certificates" issued fraudulently.

Vasco/DigiNotar will temporarily offer all SSL customers -- all of whom it says are based in the Netherlands -- a Dutch government certificate as a short-term solution. "We are also talking to browser companies in order to install a re-routing mechanism," the spokesman says.

The company also has suspended the sale of SSL and EV-SSL certificates until its latest security audit is complete.

But security experts say the problem is that if the fake certificates were used for man-in-the-middle attacks, the damage may already have been done. "This press release only has made me more worried about how much this may be just the tip of the iceberg," says Roel Schouwenberg, senior antivirus researcher for Kaspersky Lab. "The google.com cert was only revoked yesterday afternoon EST."

Schouwenberg says DigiNotar's statement raises more questions. "The conducted audit does not inspire any confidence. How did they miss the Google cert? How did they miss the website hacks pointed out by F-Secure?" he says, referring to a F-Secure Mikko Hypponen's post todayshowing what appears to be evidence of Iranian hackers having broken into DigiNotar's servers, and one page by alleged Turkish hackers back in 2009.

Hyponnen weighed in on DigiNotar's statement as well. "It raises more questions than answers. Diginotar indeed was hacked, on the 19th of July, 2011. The attackers were able to generate several fraudulent certificates, including possibly also EV SSL certificates. But while Diginotar revoked the other rogue certificates, they missed the one issued to Google. Didn't Diginotar think it's a tad weird that Google would suddenly renew their SSL certificate, and decide to do it with a mid-sized Dutch CA, of all places?" Hypponen, chief research officer of F-Secure blogged. "And when Diginotar was auditing their systems after the breach, how on earth did they miss the Iranian defacement discussed above?"

Another problem is that revocation isn't a sure thing. The rogue certs could be used for one-off, targeted attacks, and therefore would be tough to pinpoint, experts say.

"Additionally, there are ways to bypass revocation notices. So currently, we're depending on browser updates to fully protect us," Kaspersky's Schouwenberg says. "The average turnaround time is rather suboptimal. Let's hope Apple will be faster than with the Comodo case."

He says it also appears that not all of the CAs have been revoked, either: A separate DigiNotar CA handles the EV-SSL certs, and Chrome currently appears to be still accepting that CA, he says.

The big issue, of course, is the trust placed in CAs, a problem that was illuminated back in March when Comodo disclosed that nine SSL certificates -- including ones for mail.google.com, www.google.com, login.skype.com, addons.mozilla.org, login.live.com, and global trustee, and three different ones for login.yahoo.com -- had been issued by one of its European resellers after its systems were breached.

Owning a certificate authority is a valuable target for attackers, and CAs are only as secure as their own systems. Experts worry that DigiNotar hasn't found all of the rogue certificates yet, and that attacks could be ongoing and undetected. Attackers could basically impersonate Google and the other website domains to wage man-in-the-middle attacks to snoop on communications going through those sites, or for other nefarious purposes.

Like with the Comodo hack, speculation has centered around Iran, which doesn't have a CA of its own and thus would have to hack one to obtain digital certificates. "That case [Comodo's reseller hack] was tied to Iran. So is this one. It's likely the Government of Iran is using these techniques to monitor local dissidents," Hypponen said in his post.

Meanwhile, Microsoft has removed the DigitNotar root certificate from it’s the Microsoft Certificate Trust List for Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2. It's working on a fix for Windows XP and Windows Server 2003. Mozilla will issue updates to Firefox to address the rogue certs, and Google plans to do the same for Chrome.

"Today we received reports of attempted SSL man-in-the-middle (MITM) attacks against Google users, whereby someone tried to get between them and encrypted Google services. The people affected were primarily located in Iran. The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google (and has since revoked it)," said Heather Adkins, information security manager at Google in a blog post yesterday. "Google Chrome users were protected from this attack because Chrome was able to detect the fraudulent certificate."

Meanwhile, DigiNotar reiterated that most of its clients, including Dutch government business PKIOverheid, were not affected by the breach. "DigiNotar actively looks for quick and effective solutions for its existing (EV)SSL customers. The company expects to have a solution for its entire customer base before the end of this business week. DigiNotar expects that the cost of this action will be minimal," the company said in its press release.

Attackers Obtain Valid Cert for Google Domains, Mozilla Moves to Revoke It


A certificate authority in the Netherlands issued a valid SSL wildcard certificate for Google to a third party in July, leading to concerns that attackers may have been using the certificate to route sensitive traffic through their own servers, capturing it and compromising user data in the process. The certificate was revoked by the CA, DigiNotar, after the problem came to light Monday.

The attack appears to have been targeting Gmail users specifically. Some users trying to reach the Gmail servers over HTTPS found that their traffic was being rerouted through servers that shouldn't have been part of the equation. On Monday afternoon, security researcher Moxie Marlinspike checked the signatures on the certificate for the suspicious server, which had been posted to Pastebin and elsewhere on the Web, and found that the certificate was in fact valid. The attack is especially problematic because the certificate is a wildcard cert, meaning it is valid for any of Google's domains that use SSL.

It's not clear who DigiNotar issued the certificate to at this point.

Security and privacy experts began discussing the problem Monday, after some people in Iran began posting messages to Twitter and elsewhere about the possibility of a man-in-the-middle attack by the country's government, using the certificate. The certificate was issued on July 10, and Mozilla said on Monday that it is planning to isue immediate updates to many of its products, including Firefox, Thunderbird and others, to remove the DigiNotar root CA.

"Users on a compromised network could be directed to sites using a fraudulent certificate and mistake them for the legitimate sites. This could deceive them into revealing personal information such as usernames and passwords. It may also deceive users into downloading malware if they believe it’s coming from a trusted site. We have received reports of these certificates being used in the wild," Mozilla securityofficials said in a blog post.

"Because the extent of the mis-issuance is not clear, we are releasing new versions of Firefox for desktop (3.6.21, 6.0.1, 7, 8, and 9) and mobile (6.0.1, 7, 8, and 9), Thunderbird (3.1.13, and 6.0.1) and SeaMonkey (2.3.2) shortly that will revoke trust in the DigiNotar root and protect users from this attack."
The problem with the fraudulent *.google.com certificate is quite similar to the results of the attack on Comodo earlier this year in which the attackers were able to compromise one of the company's European registration authorities and issue valid SSL certs for Gmail, Yahoo, Skype and several other high-value sites.

Firefox users who want to disable the browser's trust of the DigiNotar root immediately can do so by clicking on Options, then Advanced, then Encryption and then selecting the View Certificates option. Then scroll down to the DigiNotar root CA, click on it and then click on Delete or Distrust.

Thursday, 25 August 2011

Symantec Shows Largest Growth in SSL Certificates for August and Continues to Lead Critical EV SSL Market

MOUNTAIN VIEW, Calif. – August 24, 2011 – Symantec Corp. (Nasdaq: SYMC) today announced that it achieved the largest overall SSL certificate growth in the market for August, with a gain of 19,892 total certificates for the month. Symantec remains the market share leader among all SSL certificate authorities worldwide. Symantec also demonstrated leadership in the growing extended validation (EV) SSL market, which grew overall to more than 47,000 certificates.

Extended Validation growth


Symantec was responsible for most (1,752) of this month's overall growth of 2,725 EV certificates, helping to increase the total to 47,532. Netcraft reported that Symantec leads the space with a market share of 68 percent, further demonstrating that when it comes to web security, the majority of organizations online rely on Symantec.


When a website is protected with an EV SSL Certificate, the latest high-security browsers show prominent visual cues to signal that the site has been authenticated to a higher level. For instance, Internet Explorer as well as Firefox browsers display a green address bar and a field with the name of the organization that owns the website. Both are instantly recognizable signals to consumers that they have reached a website whose identity has been certified by a recognized SSL certificate authority such as Symantec.

“The Netcraft Survey data for August clearly demonstrates that EV SSL is a growing business and that Symantec is leading the charge,” said Fran Rosch, vice president of Trust Services at Symantec. “Customers continually realize the value of working with a trusted certificate authority for SSL and EV SSL and view Symantec as a trusted partner as we continue our innovation and leadership to provide the most comprehensive product lineup and highest standards in technical support.”
Related





Connect with Symantec








About Business Solutions from Symantec



Symantec helps organizations secure and manage their information-driven world with endpoint security, messaging security, web security,data protection, identity validation and authentication, and security management solutions.


About Symantec


Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.


Note to Editors: If you would like additional information on Symantec Corporation and its products, please visit the Symantec News Room athttp://www.symantec.com/news. All prices noted are in U.S. dollars and are valid only in the United States.

Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners.