Result of an SSL error in Chrome |
DigiNotar representatives did not respond to a request for comment.
The intrusion was revealed late last month when Google said Gmail users in Iran were at risk of having their log-in credentials stolen after someone broke into DigiNotar to steal the digital equivalent of an identification card for Google.com. The problem first surfaced on a Google support site on August 28. However, DigiNotar only acknowledged last week that it had detected an intrusion into its Certificate Authority infrastructure on July 19.
The Gmail incident affected mostly Iranian users, and it now appears the certificates might have been issued for the purpose of spying on Iranian dissidents, perhaps by the Iranian government. The Tor Project's Jacob Appelbaum, who published the list of affected domains, notes that one domain certificate on the list is "a calling card from a Farsi speaker," the language spoken by most Iranians:
CN=*.RamzShekaneBozorg.com,SN=PK000229200006593,OU=Sare Toro Ham Mishkanam,L=Tehran,O=Hameye Ramzaro Mishkanam,C=IRRamzShekaneBozorg.com is a bogus address, and Appelbaum reported that "RamzShekaneBozorg" translates from Farsi to "great cracker," while "Hameyeh Ramzaro Mishkanam" translates to "I will crack all encryption" and "Sare Toro Ham Mishkanam" translates to "i hate/break your head."
Ot van Daalen, director of Bits of Freedom, a Dutch group that defends digital privacy rights, said the hacking put Iranian dissidents "at grave risk."
Appelbaum, who noted that DigiNotar's audit trail is incomplete, said the list includes certificate authority (CA) roots that should probably never be trusted again.
"The most egregious certs issued were for *.*.com and *.*.org while certificates for Windows Update and certificates for other hosts are of limited harm by comparison," Appelbaum wrote in a Tor Project post. "The attackers also issued certificates in the names of other certificate authorities such as 'VeriSign Root CA' and 'Thawte Root CA' as we witnessed with ComodoGate, although we cannot determine whether they succeeded in creating any intermediate CA certs."
SSL Error in Firefox |
This is the second time this year that the Iranian government has been linked to attempts to obtain fraudulent certificates to impersonate major Web sites. Comodo, a Jersey City, N.J.-based firm that issues digital certificates, said in March the nine certificates were fraudulently obtained. The Internet Protocol addresses used in the attack were in Tehran, Iran, said Comodo, which said that because of the focus and speed of the attack, it was "state-driven."
Kaspersky Lab's Roel Schouwenberg wrote in a blog post that the DigiNotar attack may prove to be more of a watershed moment than Stuxnet, a worm code discovered last year that is widely believed to have been designed to sabotage a uranium enrichment facility in Iran.
"The attack on DigiNotar doesn't rival Stuxnet in terms of sophistication or coordination," Schouwenberg wrote. "However, the consequences of the attack on Diginotar will far outweigh those of Stuxnet. The attack on DigiNotar will put cyberwar on or near the top of the political agenda of Western governments."
Source: http://news.cnet.com/8301-1009_3-20101786-83/dutch-firm-linked-to-many-more-fraudulent-net-certificates/#ixzz1XFTW2QmM
0 comments:
Post a Comment