GlobalSign has found evidence that its main Web server was compromised recently, but has not discovered any indications that its certificate authority infrastructure was hacked, contrary to claims by the attacker responsible for the DigiNotar CA hack.
The company, which is one of the larger CAs in the world, has been investigating claims by the Comodohacker that he has penetrated the GlobalSign CA infrastructure. It has retained Fox-IT, the same company that did the forensics of DigiNotar's systems in the wake of its attack, and GlobalSign has suspended its issuance of digital certificates until at least Monday while it finishes the investigation.
However, the company said on Friday that it had not found any direct evidence of a breach of its certificate authority systems.
"Today we found evidence of a breach to the web server hosting the www website. The breached web server has always been isolated from all other infrastructure and is used only to serve the www.globalsign.com website. At present there is no further evidence of breach other than the isolated www web server. As an additional precaution, we continue to monitor all activity to all services closely. The investigation and high threat approach to returning services to normal continues," the GlobalSign statement said.
The attacker who claims to have performed the DigiNotar intrusion has said that he also compromised four other high-profile CAs, naming GlobalSign as one of them. He has not named the other three publicly, but in the aftermath of the attack, Mozilla has asked all of the CAs in the Firefox trusted root program to perform detailed audits of their PKIs, ensure two-factor authentication is in place on systems that issue certificates and take other security precautions.
GlobalSign has said that it plans to bring some of its CA services back online on Monday. The fact that no evidence of a breach has been found so far clearly doesn't rule out the possibility that the attacker did indeed compromise the GlobalSign CA, but just means that the investigation hasn't turned up concrete evidence of an intrusion.
In a message posted to his Pastebin page this week, Comodohacker said "GlobalSign (I have access to their entire server, got DB backups, their linux / tar gzipped and downloaded, I even have private key of their OWN globalsign.com domain."
nb : threatpost
Read More...
-=WELCOME IN MY BLOG=-
11/09/11
GlobalSign Says Web Server Was Hacked, But No Signs of CA Breach
09/09/11
Certificate hacks: PKI didn't fail us, humans did
After latest attack, GlobalSign stopped issuing SSL certificates. But the real problem is that few pay attention to warnings anyway

The computer security world is aflutter because hundreds of bogus digital certificates have been issued. "It's a massive failure of PKI," they say. "It proves that there's too much trust spread around," say others.
But it's hard for me to get worked up about any public CA or PKI compromise. Here's why: Almost nobody pays serious attention to digital certificate warning messages in the first place.
I've yet to see the person who, when presented with a certificate error, didn't continue on and visit the website they were trying to access. Most users are simply annoyed by digital certificate warning messages. How dare they get in the way of a quick-loading Web page!
It's not just mom and granddad who are ignoring digital certificate warnings. A few years ago, a survey revealed that the more users knew about digital certificates and PKI, the more likely they were to ignore the warnings.
Part of the problem is that for as long as public PKI has been in existence -- nearly two decades -- it has tended to be implemented poorly. Websites with SSL certificates are notorious for having mistakes in their certificates. Mostly they have incorrect host names, where the subject name does not match the host name being contacted -- but certificates are often expired or have other x.509 mistakes. I attended a Black Hat Las Vegas 2010 conference on the subject where Ivan Ristic, directory of engineering at Qualys, revealed that the majority of websites using SSL certificates had errors.
Qualys found 22.65 million SSL-enabled websites and hosts on the Internet (out of hundreds of millions of websites). Only 720,000 had SSL certificates with a valid name match. Only 28 percent of the most popular SSL websites had a proper name, although 70 percent had digital certificates that were linked to a trusted CA. That's good. But 28 percent were untrusted, and 4 percent had trust chains that could not be verified.
Moreover, Qualys said more than 2 percent of the 22.65 million sites were suspicious. More than 137,000 certs were expired, 96,000 were self-signed, and more than 1,000 were revoked (but still being used).
Twenty-one thousand had invalid digital signatures, and more than 57,000 had unknown CAs. Ninety-nine digital certificates had known bad keys left over from the Debian random number generator vulnerability, which was found and fixed more than a year before.
I'm sure that these statistics have improved over the last year, but if only 3 percent of SSL-enabled sites (720,000 divided by 22.65 million) had a correct and valid SSL certificate (including only 28 percent of popular websites), can we really ask end-users to rely on public PKI?
Don't get me wrong: I'm sad anytime I hear that a CA is hacked. CAs have heavy, tight security around the digital certificates that can issue other certificates. Most are protected by hardware security modules (HSMs), which usually require smart cards, USB tokens, or some other physical security device. In fact, it usually takes multiple physical tokens (each attached to different people) in order to access the important digital certificates. HSMs should be used by any company with a PKI, but especially by CAs.
The Comodo hacker referenced above talks about being thwarted by an HSM. My guess is that the other compromised CAs were either not using HSMs or were not using them appropriately.
The bottom line is that PKI didn't fail us. Its mathematical beauty and potential assurance is something rare in the computer security world. If run correctly, it would greatly benefit our online world. But as with most ongoing security risks, human nature ruins the promise.
nb : infoworld
Read More...
Apple Mum On Plans To Protect Users From Diginotar SSL Hack
Apple is keeping mum about when - or if - it will blacklist SSL certificates more than a week after other browser makers moved to break trust with the disgraced Dutch certificate authority Diginotar.
With each new day revealing more about the extent of the breach, experts warn that Apple is leaving users of the company's Safari Web Browser and mobile devices vulnerable to man in the middle attacks.
Apple's Safari Web browser and iOS mobile devices have not been updated to reflect the breach at Diginotar. That means that Websites using fraudulent certificates issued by the compromised certificate authority wouldn't be treated as "high risk" by Safari or iOS-based devices like the iPhone and iPad. Apple did not not responded to multiple requests for comments on its plans to address the Diginotar compromise from Threatpost.
Competing browser vendors including Microsoft, Google and The Mozilla Foundation moved to break trust with Diginotar's compromised certificate authorities almost immediately after word of a fraudulent certificate for Google.com issued by Diginotar broke on August 27th. Both companies have taken additional steps since then to expand the reach of their bans as more information about the extent of the breach has been made public. Specialty browser makers like The Tor Project have responded in a similar fashion.
Not so, Apple, which hasn't issued an update to its Mac OSX or iOS mobile operating systems, nor its Safari Web browser to address the compromise. Nor has Apple given its tens of millions of users any concrete advice on how to protect themselves from man in the middle attacks using rogue Diginotar-issued certificates in the absence of a vendor patch. Some advice has trickled online. Coriolis Systems, an independent software firm that created the iPartition and iDefrag programs for Apple's Mac operating system, published instructions on disabling the DigiNotar root CA on their Mac systems manually, though it was subsequently revealed that doing so wouldn't entirely protect users from man in the middle attacks. The plog ps-enable has issued more exacting instructions to completely revoke trust in Diginotar from the Mac OS X keychain, the Mac's built-in password and certificate management system. However, Apple has neither endorsed nor refuted those manual workarounds.
That has left Mac and iOS users scrambling for answers on how to protect themselves. "Basically, until Apple either releases a security update with this CA cert removed, or adds a way for me to remove it myself, nobody is allowed to use iPads or iPhones for any company-related purpose at work," wrote a user with the handle John Simpson on an Apple support forum.
Roel Schouwenberg, a senior security analyst at Kaspersky Lab, said that the delay is puzzling, but that Apple was similarly slow to respond to the breach of Comodo, another certificate authority, in March.
"It's very surprising Apple isn't just going out and fixing these issues. Especially when you consider the fix should be easy and security can be leveraged as a differentiator," Schouwenberg said.
He said the delay may be linked to problems revoking EV (or "extended verification") SSL certificates in OSX. Whatever the case, he said the company's lack of communication about when or if a fix is coming is inexcusable. "If there is a technical reason for their slow response to these issues they should communicate it. Either way, their silence is not acceptable. It's all the more reason not to use Safari."
nb : threatpost
Read More...
Researcher raps Apple for not blocking stolen SSL certificates
Apple is 'dragging its feet' by not matching rivals such as Microsoft and Google in barring access to sites secured with suspect DigiNotar certificates
[ Also on InfoWorld: Debacle deepens for hacked SSL certificates issuer. | Find out how to block the viruses, worms, and other malware that threaten your business, with hands-on advice from InfoWorld's expert contributors in InfoWorld's "Malware Deep Dive" PDF guide. ]
Unlike Microsoft, which updated Windows Tuesday to block all SSL (secure socket layer) certificates issued by DigiNotar, Apple has not updated Mac OS X to do the same.
DigiNotar, one of hundreds of firms authorized to issue digital certificates that authenticate a website's identity, admitted on Aug. 30 that its servers were compromised weeks earlier. A report made public Monday said that hackers had acquired 531 certificates, including many used by the Dutch government, and that DigiNotar was unaware of the intrusion for weeks.
Because almost all the people who were routed to a site secured with one of the stolen certificates were from Iran, many experts suspect that the DigiNotar hack was sponsored or encouraged by the Iranian government, which could use them to spy on its citizens.
Microsoft isn't the only software maker to block all DigiNotar certificates: Google, Mozilla, and Opera have also issued new versions of their browsers -- Chrome, Firefox, and Opera -- to completely, or in Opera's case, partially prevent users from reaching websites secured with a DigiNotar certificate.
Users of Safari on Mac OS X, however, remain at risk to possible "man-in-the-middle" attacks based on the fraudulently obtained certificates.
And that rubbed Henry the wrong way. "Mac users have been left hanging in the wind," Henry said.
Because Safari relies on the underlying operating system to tell it which certificates have been revoked or banned entirely, Apple must update Mac OS X. The Windows edition of Safari, which has a negligible share of the browser market, taps Windows' certificate list: That version is safe to use once Microsoft's Tuesday patch is applied.
Henry admitted he wasn't surprised by the fact that Apple was odd-man out.
"No, I'm not, not after it took them a month to respond to the Comodo issue," Henry said, referring to a smaller-scale hack of another certificate authority last March.
Then, Apple updated Mac OS X on April 14, nearly a month after Comodo discovered the intrusion and began notifying browser makers. Microsoft had patched Windows to block the stolen Comodo certificates on March 23, while Google and Mozilla had even earlier.
The DigiNotar hack, however, was larger -- criminals acquired only nine certificates from Comodo -- and more serious in that the Dutch government relied on DigiNotar to secure its websites.
And then there are the boasts made by an unidentified hacker who has claimed responsibility for both the Comodo and DigiNotar breaches.
On Monday, that hacker -- known only as "Comodohacker" -- also asserted that he had penetrated four other CAs, or certificate authorities, including GlobalSign, a U.S.-based CA much more widely used than DigiNotar.
Tuesday, GlobalSign suspended certificate sales and said it had launched an investigation into Comodohacker's claims. A day later the New Hampshire company said it had hired Fox-IT, the forensics firm that is still digging into the DigiNotar hack for the Dutch government.
If Comodohacker's claims are accurate, and there are other CAs besides DigiNotar that have issued unauthorized SSL certificates, Apple's sluggishness is even more inexcusable, Henry said.
"We may be looking at the tip of the iceberg," said Henry. "If there are four other CAs [involved] as this guy claims, we could be in a hell of a mess in the next few months. We'll be playing catch-up, but that seems to be more difficult for Apple than for Microsoft, or Google and Mozilla."
But Henry didn't limit his criticism to Apple.
"What about smartphones ?" he asked. "I'm not aware of a single carrier or vendor that has pushed out a browser update for this."
Neither Google nor Apple have said anything about plans for updating Android or iOS to follow the road taken by most desktop browsers. The companies declined to comment Tuesday for a story written by IDG News Service reporter Robert McMillan. (Like Computerworld, IDG News is part of IDG.)
According to Web metrics company Net Applications, about three-out-of-four Mac OS X users run Safari as their primary browser.
Until Apple updates Mac OS X, users should browse with Chrome or Firefox, Henry said. Neither requires Mac OS X to be updated to block all DigiNotar certificates.
nb : infoworld Read More...
08/09/11
Are Some Certificate Authorities Too Big To Fail?
In the wake of this weekend's revelations of the seriousness of the attack on certificate authority DigiNotar, security experts have renewed criticism of the Internet's digital certificate infrastructure, with some wondering if larger certificate authorities (CAs) might be too big to fail.
DigiNotar's network had significant security weaknesses that allowed an attacker to issue an unknown number of untraceable certificates, a report by Dutch security firm Fox-IT found. The situation has led the Dutch government to take over operations of the CA, and major browser vendors to patch their products, breaking the trust their software has of secure-sockets layer (SSL) certificates issued by DigiNotar.
Revoking Diginotar’s authority was necessary because the company failed to secure its infrastructure, allowing an unknown number of certificates to be created, says Moxie Marlinspike, chief technology officer of startup mobile security firm Whisper Systems. The result will likely be that DigiNotar will not survive as a certificate authority.
"It's not a simple matter of removing certificates from a database, because they're not in any databases," says Marlinspike, who presented an alternative approach to the current SSL infrastructure last month at DEFCON. "We may never track them all down."
While revoking trust in Diginotar may help bring that crisis to a close, Marlinspike is among a large number of security researchers who worry that larger firms such as Comodo or VeriSign may likewise be vulnerable. Unlike Diginotar, those larger certificate authorities may be “too big to fail” – forcing browser makers to keep them on their lists of trusted issuers out of fear of the disruption that blacklisting them would cause.
In March, certificate authority Comodo acknowledged that an attacker had been able to issue at least nine certificates for major domains, such as Google and Yahoo. However, because of the limited nature of the breach, browser makers decided only to revoke the fraudulent certificates.
Yet it is unclear whether a more significant breach would have resulted in Comodo losing its authority, says Peter Gutmann, a researcher in computer science at the University of Auckland.
"Once you've issued enough (certificates), the browser vendors won't pull your CA cert any more because it would affect too many people," Gutmann says. "This is what saved Comodo. In Diginotar's case they were small enough that the browser vendors could pull their certs."
Mozilla justified its decision to rescind trust in DigiNotar by noting that the extent of the breach is still unknown, that DigiNotar failed to notify the public in a timely manner, and that attacks using the certificates have been document in the wild, Johnathan Nightingale, Director of Firefox Engineering, stated in a post on Friday.
"The integrity of the SSL system cannot be maintained in secrecy," Nightingale wrote. "Incidents like this one demonstrate the need for active, immediate and comprehensive communication between CAs and software vendors to keep our collective users safe online."
Comodo argues that it avoided that kind of “worst case” scenario because it had a diverse set of defenses in place to limit the breach.
As certificate authorities grow, so does their responsibility to provide better security, he said. "Larger CAs should have more resources for monitoring, detecting and reacting quickly to these kind of attacks," said Melih Abdulhayoglu, CEO of Comodo. "If you remember Comodo reacted within minutes and provided transparency to the world in a timely manner."
Security researchers, however, argue that the best defense against a breach at a certificate authority is for browser makers to find other ways to ensure online safety.
"I might say that concentrating all risk in a single, failure-prone mechanism that has been shown to have zero effect in stopping the bad guys is a really, really bad idea," says the University of Auckland's Gutmann.
Part of the problem is that attacks on third-party trust providers such as Comodo, RSA and DigiNotar are a new trend, says Jeff Hudson, CEO of Venafi, a maker of certificate management software. As security professionals focus on the problem, better policies will be put in place that will mitigate the threat of a major breach at a large CA.
Rather than place total trust in a CA, for example, users in the future might be able to decide who to trust or have a sliding scale of risk. A valid certificate, brand-name domain and valid domain-name record would be positive factors. A certificate issued by a compromised CA, for example, a suspicious DNS record, or just-issued certificate would be negative factors.
For now, however, companies that rely on SSL certificates for their business need to be prepared for the worst, Hudson says.
"Right now, the state of preparedness for failure is dismal," he says. "People have to recognize this and be ready. You have to know who your trust providers are, where you assets are, and be ready to swap out a provider's certificates in hours."
nb : threatpost
Read More...
GlobalSign Stops Issuing Certs As It Investigates Claims of Compromise
GlobalSign, a major certificate authority that was named by the hacker who has claimed credit for the DigiNotar hack as another CA he has compromised, has stopped issuing certificates for the time being while it investigates the claims and determines whether its network has in fact been compromised. It also has hired Fox-IT, the same company that investigated the attack at DigiNotar, to perform the audit of its systems.The company said on Tuesday that it made the decision after seeing the message posted by the attacker known as Comodohacker on Pastebin, in which he said that he had compromised four other high-profile CAs in addition to DigiNotar, explicitly naming GlobalSign as one of them.
"On Sep 5th 2011 the individual/group previously confirmed to have hacked several Comodo resellers, claimed responsibility for the recent DigiNotar hack. In his message posted on Pastebin, he also referred to having access to 4 further high profile Certificate Authorities, and named GlobalSign as one of the 4," GlobalSign said in a statement.
"GlobalSign takes this claim very seriously and is currently investigating. As a responsible CA, we have decided to temporarily cease issuance of all Certificates until the investigation is complete. We will post updates as frequently as possible."
GlobalSign officials said on Wednesday that the company has retained Fox-IT, a Dutch security firm, to help conduct the investigation into a possible breach of its system.
In his messages on Pastebin posted Tuesday, Comodohacker said that he had attacked DigiNotar in retaliation for the Srebrenica massacre in 1995 and that he had also compromised four other CAs and still had the ability to issue himself all manner of certificates from them. In one message, the attacker said that despite Microsoft's claims to the contrary, he still had the ability to send updates from the Windows Update domain. That domain is one of the ones for which he had obtained a certificate from DigiNotar.
"I'm able to issue windows update, Microsoft's statement about Windows Update and that I can't issue such update is totally false! I already reversed ENTIRE windows update protocol, how it reads XMLs via SSL which includes URL, KB no, SHA-1 hash of file for each update, how it verifies that downloaded file is signed using WinVerifyTrust API, and... Simply I can issue updates via windows update!" the message said in part.
Microsoft has issued an update for Windows users that revokes the trust for all of the DigiNotar root certificates, effectively making all of the certificates issued by the company untrusted in Windows.
nb : threatpost Read More...
07/09/11
Debacle deepens for hacked SSL certificates issuer
Report indicates widespread compromise of DigiNotar's infrastructure and questions industry's response to breaches

The report by Dutch security firm Fox-IT (PDF) found at least 531 certificates had been fraudulently created by an intruder into their systems, an increase from last week's estimate of more than 270. The attacker gained administration rights to firm's domain server, which managed all of DigiNotar's certificate infrastructure, a significant network weakness, the report stated.
"All CA [certificate authority] servers were members of one Windows domain, which made it possible to access them all using one obtained user/password combination," the report stated. "The password was not very strong and could easily be brute-forced."
More than 300,000 unique IP addresses -- almost entirely from Iran -- validated a fraudulent certificate issued for Google's domain. Each time a browser encounters a new certificate, the software checks its validity with DigiNotar. The fact that nearly all the validation checks came from Iran could indicate that the nation's government may have been involved in the attack. The Dutch government is currently investigating the possibility.
The breach of DigiNotar and its aftermath has caused security experts to question the capability of the SSL certificate infrastructure -- responsible for issuing and verifying signatures used to secure online communications and transactions -- to respond to major security events. Major browser makers, including Google and Microsoft, have issued patches that will invalidate all certificates issue by DigiNotar. Yet the impact of the breach goes beyond just browsers: Certificates were issued for Microsoft's Windows Update mechanism and Google's Android code signatures.
Add to that the uncertainty regarding the breach and the industry will feel the effects of the attack for months, if not longer.
"With some 500 authorities out there globally, it's hard to believe Diginotar is the only compromised CA out there," Roel Schouwenberg, senior researcher for security firm Kaspersky, said in a blog post. "DigiNotar will quite likely go out of business. This should serve as a very strong message for CAs to go public with any breach."
On Monday, the hacker that claimed responsibility for breaching certificate authority Comodo, posted an online statement taking credit for the DigiNotar hack. While the timing -- a statement coming much later than the attack and coinciding with the issuance of the Fox-IT report -- suggested mere braggadocio, details found by the security firm corroborated the hacker's claims. Specifically, a specialized script intended to exfiltrate certificates also included a statement taunting DigiNotar.
"In the text, the hacker left his fingerprint: Janam Fadaye Rahbar," the report stated. "The same text was found in the Comodo hack in March of this year."
The Dutch government has taken over operations of the certificate authority, which is a subsidiary of security firm VASCO, after declaring the company's authentication infrastructure untrusted.
nb : infoworld Read More...
GlobalSign stops issuing SSL certificates in response to Iranian hacker
Earlier today a person calling himself ComodoHacker made a submission to text posting site Pastebin.com. Similar to a previous post by ComodoHacker it is fair to call it a bit of a bragging rant.
Last March ComodoHacker claimed responsibility for the first attack against a certificate authority that resulted in bogus SSL certificates being issued in the wild.
In addition to claiming his attacks are far more sophisticated than Stuxnet and distancing himself from the Iranian government, he also claims to have compromised four other certificate authorities, including GlobalSign.
GlobalSign, the fifth largest certificate issuer according to NetCraft, responded to this news by immediately ceasing any further signing of certificates while they investigate.
Their response is interesting. While we don't know if they have been compromised (and arguably, neither do they) they are making a tough choice that is what we should expect from organizations whose business models rely on trust.
It's possible the accusations are simply from an anonymous raving lunatic. Yet they could be true, and rather than put the greater internet community at risk, GlobalSign is forgoing some revenue out of an abundance of caution.
That's great news. Let's hope that the accusations are false and everything is safe and secure at GlobalSign and the other three unnamed victims.
While I have argued for a long time that the certificate system is fragile and arguably broken, I'd rather not have two examples in one week to support my arguments.
nb : nakedsecurity.sophos
Read More...
![[+]d'ZheNwaY's Blog[+]](http://feeds.feedburner.com/blogspot/YRtWp.1.gif)
