23 Mar 2011
The major browser developers have released patches to deal with SSL certificates which were stolen from certificate authority Comodo earlier this month.
Firefox, Chrome and Internet Explorer have all been patched to deal with the fake certificates and other manufacturers are following suit.
The incident began on 15 March with a hacking attack on a southern European partner of Comodo.
Nine fake SSL certificates were requested for sites, including Google, Microsoft Skype and Yahoo, and at least one was issued before the attack was detected and terminated. Comodo immediately revoked the certificates and informed the necessary parties.
The resultant activity was picked up by the Tor Project, which noticed Google's Chromium engine making changes to block the SSL certificates, followed by a full Chrome update a day later. Tor agreed to embargo the news until patches had been issued.
Comodo's chief executive Melih Abdulhayoglu told V3.co.uk that he believed the attack came from the Iranian government.
"Our security was good in that we picked up the attack and shut it down quickly, but we should have covered this threat model," he said. "We didn't, however, model for attack from a foreign government."
Abdulhayoglu identified three clues to the attacker's origin. Firstly the choice of targets was not financial companies but core internet infrastructure sites.
Secondly, in order for the certificates to be of any use, access to the domain name system infrastructure would have been required.
Finally, the attack itself did not bear the hallmarks of criminal attacks the company had experiencee with in the past. It was very well orchestrated and "too clean", according to Abdulhayoglu.
"You can't be 100 per cent certain," he said. "But if it looks like a duck, and quacks like a duck, then it probably is a duck."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Flash Developer- Actionscript 3.0, AJAX, JSON, computer...
Business Analyst - Risk platform - Equity Derivatives...
Java Developer - Algorithmic Trading - Global Trading...
Junior Middle Office Project Manager, Treasury, IB...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
bkock
i had a problem that night ti comodo block me going on line with internet explorer i had delet comodo a nd put on avg i could get on line with crome and firfox but nouthing else
Posted by: DEREK FAULKNER 24 Mar 2011
Impressive response
It's good to read how effectively the 'good guys' responded to this incident. However, it would be nice to be told which browser versions are vulnerable and which versions have been patched.
Posted by: Chris 24 Mar 2011