All the latest UK technology news, reviews and analysis

Mozilla's Firefox Add-ons site affected by DigiNotar certificate scam

by Phil Muncaster

01 Sep 2011

Be the first to comment

  • Tweet this

Mozilla Firefox logo

 

It has emerged that the Mozilla Firefox add-ons web page was affected in the same scam that saw Dutch SSL certificate authority DigiNotar issue fraudulent certificates for various sites including Google.com.

Director of Firefox engineering Johnathan Nightingale responded to V3 in a statement: "DigiNotar informed us that they issued fraudulent certs for addons.mozilla.org in July, and revoked them within a few days of issue.

"In the absence of a full account of mis-issued certificates from DigiNotar, the Mozilla team moved quickly to remove DigiNotar from our root program and protect our users."

DigiNotar parent company Vasco admitted in a release on Tuesday that several certificates were erroneously issued after an "intrusion into its certificate authority infrastructure" on 19 July.

"At that time, an external security audit concluded that all fraudulently issued certificates were revoked," the company added at the time.

"Recently, it was discovered that at least one fraudulent certificate had not been revoked at the time. After being notified by Dutch government organisation Govcert, DigiNotar took immediate action and revoked the [Google.com] fraudulent certificate."

Mozilla did not say whether the hackers managed to use the fraudulent certificates to launch man-in-the-middle attacks on Firefox users before the certificates were revoked.

Google, on the other hand, admitted that such attacks had been attempted mainly against Iranian users using the relevant stolen certificate.

To many, the news of another certificate authority being compromised just months after the Comodo debacle is proof that the current system for authenticating web sites is broken.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

2%

15%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Web Developer (ASP.NET C#) - Leeds / Yorkshire

ASP.NET Web Developer ( ASP.NET, C#, SQL Server, CSS...

Technical Consultant, Back Office (IMMEDIATE STARTERS)

THIS ROLE IS LOOKING AT IMMEDIATE STARTERS AND WITH MULTI...

Sales Consultant - Datacentre

Sales Consultant - Data Centre, Colocation, Hosting...

Senior Interaction Designer (User Experience, UCD, Prototypes)

Senior Interaction Designer (User Experience, UCD, Interactive...

To send to more than one email address, simply separate each address with a comma.