Comodo root canal call as more hacks confirmed

 

Too many SSL certificate resellers?

Comodo chief technology officer Robin Alden has admitted that two other SSL registration authorities (RAs) that resold its web certificates were compromised by the “Comodo hacker”.

“Two further RA accounts have since been compromised and had RA privileges withdrawn,” Alden wrote on Mozilla’s Bugzilla mailing list on Wednesday. 

“No further mis-issued certificates have resulted from those compromises,” he said. 

Last week Comodo, a privileged Certificate Authority (CA), warned customers that an attacker had issued nine false SSL certificates after hacking its Italian reseller, InstantSSL.it.

The fraudulent certificates could allow an attacker to launch a man-in-the-middle attack where a fake website would be verified as authentic. 

Alden’s admission came after the “Comodo hacker” revealed that he had hacked three of Comodo’s resellers [Line 20], not just InstantSSL.  

“I owned 3 of them, not only Italian one, but I interested more in Italian brach because they had too many codes, works, domains, (globaltrust, cybertech, instantssl, etc.) so I thought they are more tied with Comodo,” the hacker claimed earlier.

Alden said that Comodo had not considered the possibility of this type of targeted attack.

“We were dealing with the threat model that the RA could be underperforming with, or trying to avoid doing, their validation duty (neither of which were the case for this RA),” he said. 

“What we had not done was adequately consider the new (to us) threat model of the RA being the subject of a targeted attack and entirely compromised.”

The hacker has claimed to be an Iranian programmer seeking revenge for the Stuxnet malware, widely reported to have damaged Iran’s nuclear enrichment equipment.

On Tuesday, the hacker revealed the private key for Mozilla's "add on" certificate, which only the attacker or the authority could have held, according to Netcraft security researcher Paul Mutton.

Alden said Comodo would roll out two factor tokens to authenticate its RAs in the coming weeks and in the meantime would review all of their validation processes. 

But its effort to tighten control over reseller processes are too little too late, according to a Dutch SSL certificate reseller.

It's definitely time that Mozilla, Microsoft and others take responsibility and pull the root from the browsers,” Paul van Brouwershaven, chief technology officer for Dutch web host, Networking4all, told iTNews in an email. 

A root certificate identifies a primary CA and is often assumed to be trustworthy since it holds the highest authority. Mozilla’s list of Root CAs can be found here.

“Comodo had several opportunities to show that they are willing to change. In the past years they have showed over and over again that they are not willing to take the responsibility that a CA should have,” said van Brouwershaven. 

The main problem with Comodo -- the third largest SSL certification authority behind Verisign and Go Daddy, according to UK security firm Netcraft -- was that it failed to validate its reseller’s procedures for issuing certificates on its behalf. 

"Networking4all was able to become a Comodo RA many years ago, we never had training and we never got checked," said van Brouwershaven, adding that it could have issued "every certificate we would like."

Van Brouwershaven pointed to Comodo reseller Certstar, which in 2008 mis-issued a SSL certificate for the ‘mozilla.com’ domain.

"They where able to do this because the validation procedure from Comodo lacks. You can't trust 'hundreds' of RAs,” he said.

Van Brouwershaven also criticised Comodo’s sluggish response to a fellow Dutch reseller that had intentionally "mis-issued" certificates for a website that gave access to Dutch government agencies and the country’s major banks. 

“Only after I had notified Comodo the certificates got revoked but still nothing changed,” he said. 

Mozilla too has raised the possibility of un-trusting all of Comodo’s roots amongst several other options it wants considered for security over the coming five years.    

Copyright © iTnews.com.au . All rights reserved.


Comodo root canal call as more hacks confirmed
 
 
 
 
Top Stories
NBN Co could miss revised June fibre targets
Analysis: Cutting it fine in the race to the line.
 
Review: Sydney's Opal smartcard
It's no Oyster card.
 
Rackspace puts price premium on Aussie public cloud
At least 17 percent more compared to US instances.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Vivek Kundra on Australia's 'cloud last' policy
Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Latest Comments
Polls
Will you quit any cloud services in light of PRISM?

   |   View results
Yes
  61%
 
No
  39%
TOTAL VOTES: 70

Vote