iTnews
  • Home
  • News
  • Technology
  • Security

Hackers fake SSL certificates for web services

By Ry Crozier
Mar 24 2011 11:17AM
Follow google news

Sophisticated attack thought to be state-sponsored.

Hackers have broken into the systems of a web authentication firm in Europe, issuing false certificates that forced Google, Microsoft and Mozilla to issue emergency browser patches.

Hackers fake SSL certificates for web services

The March 15 attack on a "trusted partner" of secure socket layer (SSL) certificate issuer Comodo sent shockwaves through the web industry after Comodo suggested that it may have been the work of a "government attempting surveillance of Internet use by dissident groups".

"The attack and the suspected motivation require urgent attention of the entire security field," Comodo said in a blog post.

Nine fake SSL certificates that were issued using the compromised systems had been revoked by Comodo within "hours" of the attack being detected.

The certificates were issued for domains owned by Google, Yahoo, Skype, Mozilla and Microsoft Live.

Google appeared to be first among those firms to issue a fix to automatically block the fake certificates from being used with Chrome.

"This release blacklists a small number of HTTPS certificates," Google said in a short release statement.

Mozilla this week updated Firefox versions 4.0, 3.6, and 3.5, and Microsoft issued its own "mitigation update" a day later.

"One of the [fake] certificates potentially affects Windows Live ID users via login.live.com," Microsoft said in a security advisory.

"These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against end users. We are unaware of any active attacks."

Comodo said that "at no time were any [of its] root keys, intermediate [certificate authorities] or secure hardware compromised."

"An attacker obtained the username and password of a Comodo Trusted Partner in Southern Europe," Comodo said.

"We are not yet clear about the nature or the details of the breach suffered by that partner other than knowing that other online accounts (not with Comodo) held by that partner were also compromised at about the same time."

The trusted partner was a so-called registration authority (RA), which processed requests for digital certificates before forwarding those requests to a certification authority to issue the actual certificate.

Comodo said the attacker was "still using the account when the breach was identified and the account suspended".

"They may have intended to target additional domains had they had the opportunity," the company said.

Comodo said the attack appeared to have originated from within Iran but noted that could be just an attempt by the hackers "to lay a false trail".

However, in a post-incident report, the company indicated a belief that the attack was very likely "state-driven", given its relative sophistication.

The hack has already become known as #comodogate on popular microblogging site Twitter.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
authoritybreachcertificatecomodofakegooglehackhackersecuritysslyahoo

Related Articles

  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
Join our WhatsApp Channel

Partner Content

You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
AI is delivering business value today
Partner Content AI is delivering business value today

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.