Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow DigiNotar Security Incident (Certificate)
EH-Net
May 20, 2013, 02:54:05 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: DigiNotar Security Incident (Certificate)  (Read 19755 times)
0 Members and 1 Guest are viewing this topic.
Agoonie
Full Member
***
Offline Offline

Posts: 176



View Profile WWW
« on: August 30, 2011, 01:24:32 PM »


It looks like it is time to check your browsers for this cert.  Many are suggesting on your *nix boxes to use:

cd /etc/ssl/certs/
rm DigiNotar_Root_CA.pem

It seems like SSL is really getting hit these days.  And I do not think EV-SSL certs are going to save the day...


http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
cd1zz
Hero Member
*****
Online Online

Posts: 561


View Profile WWW
« Reply #1 on: August 30, 2011, 03:25:34 PM »

Its kind of a broken system. Moxie has great talks on this. If you allow just about anyone to be a CA or if you're a CA and have shitty security practices, then it ruins the integrity of the entire system. If we cant count on CAs to provide valid certs to legit companies then what good is it? At least the communication channel is encrypted.
Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #2 on: August 30, 2011, 03:33:08 PM »

Moxie introduced his alternative for the current CA structure this year at BlackHat/DEFCON:

http://convergence.io/index.html

Has anybody had a chance to check it out?

I just came across this via Twitter: http://codereview.chromium.org/7791032/diff/2001/net/base/x509_certificate.cc
« Last Edit: August 30, 2011, 04:46:29 PM by lorddicranius » Logged

GSEC, eCPPT, Sec+
Agoonie
Full Member
***
Offline Offline

Posts: 176



View Profile WWW
« Reply #3 on: August 30, 2011, 08:11:43 PM »

Its kind of a broken system. Moxie has great talks on this. If you allow just about anyone to be a CA or if you're a CA and have shitty security practices, then it ruins the integrity of the entire system. If we cant count on CAs to provide valid certs to legit companies then what good is it? At least the communication channel is encrypted.

I remember that especially when he released sslstrip.  I just knew it was only a matter of time after that.  I guess a broken system on its way to being crushed.  But it will be interesting to see alternatives implemented.  I remember being at a talk by Marcus Ranum and he wanted to change AV since that has been defeated, crushed and left for dead.  He had some good interesting ideas of changing the "already too late" paradigm.  But we will see.  I know we need to have something or more dark days ahead. 


Moxie introduced his alternative for the current CA structure this year at BlackHat/DEFCON:

http://convergence.io/index.html

Has anybody had a chance to check it out?

I just came across this via Twitter: http://codereview.chromium.org/7791032/diff/2001/net/base/x509_certificate.cc


I am checking that out now.  Thanks for the links!
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #4 on: August 31, 2011, 01:45:39 AM »

be aware: Diginotar just revealed that there might me more certificates given out to the wrong people. Funny detail: the whole Dutch government has Diginotar certs, including sites to do taxes etc.
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #5 on: August 31, 2011, 09:18:22 AM »

It all comes down to cost, suddenly paying a couple hundred dollars a year for a cert may not be so bad (Verisign).  All these other companies charge pennies in comparison.  I would say if you are any major player on the web then you are better off with a higher end CA for your site certs.  If anything if they get breached, you can get them for more damages. :-p  But seriously, companies want to save money so the $70 cert is much more attractive than the $600 cert.  You get what you pay for. 

Might as well install your own CA and just use self signed Cheesy
Logged

Certs: GCWN
(@)Dewser
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #6 on: August 31, 2011, 01:55:36 PM »

Here's a vid of Moxie's preso at BlackHat this year entitled "SSL and the Future of Authenticity"

http://www.youtube.com/watch?v=Z7Wl2FW2TcA

It's a great video, really funny and informative.
« Last Edit: August 31, 2011, 02:37:23 PM by lorddicranius » Logged

GSEC, eCPPT, Sec+
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #7 on: September 01, 2011, 02:34:29 AM »

Might as well install your own CA and just use self signed Cheesy

there you go, problem fixed Wink
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.