Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DigiNotar's mother company Vasco finally released a press statement.

http://www.vasco.com/company/press_room/news_archive/2011/ne...

Just incredible: They were hacked and they knew it, then forgot to clean up a certificate the hackers generated.

  On July 19th 2011, DigiNotar detected an intrusion into 
  its Certificate Authority (CA) infrastructure, which 
  resulted in the fraudulent issuance of public key 
  certificate requests for a number of domains, including 
  Google.com.

  Once it detected the intrusion, DigiNotar has acted in 
  accordance with all relevant rules and procedures.
  
  At that time, an external security audit concluded that 
  all fraudulently issued certificates were revoked. 
  
  Recently, it was discovered that at least one fraudulent 
  certificate had not been revoked at the time.  After 
  being notified by Dutch government organization Govcert, 
  DigiNotar took immediate action and revoked the 
  fraudulent certificate.

  The attack was targeted solely at DigiNotar's Certificate 
  Authority infrastructure for issuing SSL and EVSSL 
  certificates. No other certificate types were issued or 
  compromised. DigiNotar stresses the fact that the vast 
  majority of its business, including his Dutch government 
  business (PKIOverheid) was completely unaffected by the 
  attack.
Maybe directly, certainly not indirectly.


This (Dutch) article http://tweakers.net/nieuws/76466/hackers-genereerden-zelf-ve... quotes the spokesperson for DigiNotar, and he claims "we hope that by end of the week our certificates will be trusted by Google, Mozilla and Microsoft again"


FF nightly builds also block the PKIOverheid CA which signs the certificates for key Dutch government websites and services (DigiD). Mozilla is going to have a fun time with Dutch users/Dutch Government/DigiNotar


My understanding is that what Mozilla is going to ship will not block PKIOverheid. See https://bugzilla.mozilla.org/show_bug.cgi?id=682956#c17


a number of domains, including Google.com

But nowhere do they appear to include a list of these domains...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: