Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 92 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow DigiNotar Security Incident (Certificate)
EH-Net
May 26, 2012, 05:33:40 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: DigiNotar Security Incident (Certificate)  (Read 11406 times)
0 Members and 1 Guest are viewing this topic.
Agoonie
Full Member
***
Offline Offline

Posts: 142



View Profile
« on: August 30, 2011, 01:24:32 PM »


It looks like it is time to check your browsers for this cert.  Many are suggesting on your *nix boxes to use:

cd /etc/ssl/certs/
rm DigiNotar_Root_CA.pem

It seems like SSL is really getting hit these days.  And I do not think EV-SSL certs are going to save the day...


http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx
Logged

OSCE, OSCP, OSWP, CISSP, MEH...
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #1 on: August 30, 2011, 03:25:34 PM »

Its kind of a broken system. Moxie has great talks on this. If you allow just about anyone to be a CA or if you're a CA and have shitty security practices, then it ruins the integrity of the entire system. If we cant count on CAs to provide valid certs to legit companies then what good is it? At least the communication channel is encrypted.
Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 396



View Profile WWW
« Reply #2 on: August 30, 2011, 03:33:08 PM »

Moxie introduced his alternative for the current CA structure this year at BlackHat/DEFCON:

http://convergence.io/index.html

Has anybody had a chance to check it out?

I just came across this via Twitter: http://codereview.chromium.org/7791032/diff/2001/net/base/x509_certificate.cc
« Last Edit: August 30, 2011, 04:46:29 PM by lorddicranius » Logged

Agoonie
Full Member
***
Offline Offline

Posts: 142



View Profile
« Reply #3 on: August 30, 2011, 08:11:43 PM »

Its kind of a broken system. Moxie has great talks on this. If you allow just about anyone to be a CA or if you're a CA and have shitty security practices, then it ruins the integrity of the entire system. If we cant count on CAs to provide valid certs to legit companies then what good is it? At least the communication channel is encrypted.

I remember that especially when he released sslstrip.  I just knew it was only a matter of time after that.  I guess a broken system on its way to being crushed.  But it will be interesting to see alternatives implemented.  I remember being at a talk by Marcus Ranum and he wanted to change AV since that has been defeated, crushed and left for dead.  He had some good interesting ideas of changing the "already too late" paradigm.  But we will see.  I know we need to have something or more dark days ahead. 


Moxie introduced his alternative for the current CA structure this year at BlackHat/DEFCON:

http://convergence.io/index.html

Has anybody had a chance to check it out?

I just came across this via Twitter: http://codereview.chromium.org/7791032/diff/2001/net/base/x509_certificate.cc


I am checking that out now.  Thanks for the links!
Logged

OSCE, OSCP, OSWP, CISSP, MEH...
j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #4 on: August 31, 2011, 01:45:39 AM »

be aware: Diginotar just revealed that there might me more certificates given out to the wrong people. Funny detail: the whole Dutch government has Diginotar certs, including sites to do taxes etc.
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #5 on: August 31, 2011, 09:18:22 AM »

It all comes down to cost, suddenly paying a couple hundred dollars a year for a cert may not be so bad (Verisign).  All these other companies charge pennies in comparison.  I would say if you are any major player on the web then you are better off with a higher end CA for your site certs.  If anything if they get breached, you can get them for more damages. :-p  But seriously, companies want to save money so the $70 cert is much more attractive than the $600 cert.  You get what you pay for. 

Might as well install your own CA and just use self signed Cheesy
Logged

Certs: GCWN
lorddicranius
Sr. Member
****
Offline Offline

Posts: 396



View Profile WWW
« Reply #6 on: August 31, 2011, 01:55:36 PM »

Here's a vid of Moxie's preso at BlackHat this year entitled "SSL and the Future of Authenticity"

http://www.youtube.com/watch?v=Z7Wl2FW2TcA

It's a great video, really funny and informative.
« Last Edit: August 31, 2011, 02:37:23 PM by lorddicranius » Logged

j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #7 on: September 01, 2011, 02:34:29 AM »

Might as well install your own CA and just use self signed Cheesy

there you go, problem fixed Wink
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.