I wonder how many breaches never see the light of day.

Quite late but at least confirmed, VeriSign was hacked and they don’t even know what was the impact of this attack.

Comodo, DigiNotar, Verisign… did I forget some company which CA/SSL infrastructure has been compromised?

Written on February 3rd, 2012 , Debian, Internet, Linux, Security Tags: ,

Leave a Reply

Your email address will not be published. Required fields are marked *

*


8 − three =

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> <pre lang="" line="" escaped="" highlight="">

COMMENTS
    Tobias commented

    StartCom/StartSSL?

    Reply
    February 4, 2012 at 10:59 am
    Marek commented

    StartSSL (Israeli)

    http://www.internet-security.ca/internet-security-news-archives-031/security-firm-start-ssl-suffered-a-security-attack.html

    But:

    “The hackers behind the attack on StartCom failed to obtain any certificates that would allow them to spoof websites in a similar fashion, and they were also unsuccessful in generating an intermediate certificate that would allow them to act as their own certificate authority, Nigg said in an email.”

    Reply
    February 4, 2012 at 2:23 pm
    Blissex commented

    When I mentioned an ancient saying by a data center manager about storage “As far as we know we never had an undetected storage error”, a brilliant friend pointed out that it applies to successful security breaches too:

    “As far as we know we never had an undetected security breach”

    :-)

    Reply
    February 6, 2012 at 12:49 pm

fenski.pl is proudly powered by WordPress and the Theme Adventure by Eric Schwarz
Entries (RSS) and Comments (RSS).

fenski.pl

If anything can go wrong, it will