Symantec fires staffers after release of bogus Google certs

By

Testing certificates leaked.

Security vendor Symantec has sacked a number of employees for issuing fake, internal testing digital certificates for Google, at least one of which leaked onto the internet.

Symantec fires staffers after release of bogus Google certs

The certificates were issued on September 15 Australian time by Symantec subsidiary Thawte for three domains that the company did not name. Symantec did not disclose how many testing certificates were released, saying only that it was "a small number".

It has since been revealed that Thawte issued extended validation (EV) certificates for google.com and www.google.com. EV certificates are issued to provide a greater level of authentication to sites and domains than standard certificates.

Although Symantec stated that "all of these test certificates and keys were always within our control and were immediately revoked when we discovered the issue," Google found one of the digital bona-fides, as did certificate provider Digicert.

Google updated the revocation metadata in its Chrome web browser to include the public key for the mis-issued Thawte certificate, which was only valid for a single day. The online giant does not believe its users were at any risk because of the bogus certificate.

As a result of the issuance of the bogus certificates, Symantec said it had fired those responsible.

"Despite their best intentions, this failure to follow policies has led to their termination after a thoughtful review process.

"Because you rely on us to protect the digital world, we hold ourselves to a 'no compromise' bar for such breaches. As a result, it was the only call we could make," Symantec's Quentin Liu and Charlene Mike-Billstrom said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

"Widespread data theft" hits Salesforce customers via third party

"Widespread data theft" hits Salesforce customers via third party

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Home Affairs adds SecOps to new cyber risk overhaul

Home Affairs adds SecOps to new cyber risk overhaul

Log In

  |  Forgot your password?