I wonder how many breaches never see the light of day.
Quite late but at least confirmed, VeriSign was hacked and they don’t even know what was the impact of this attack.
Comodo, DigiNotar, Verisign… did I forget some company which CA/SSL infrastructure has been compromised?
StartCom/StartSSL?
StartSSL (Israeli)
http://www.internet-security.ca/internet-security-news-archives-031/security-firm-start-ssl-suffered-a-security-attack.html
But:
“The hackers behind the attack on StartCom failed to obtain any certificates that would allow them to spoof websites in a similar fashion, and they were also unsuccessful in generating an intermediate certificate that would allow them to act as their own certificate authority, Nigg said in an email.”
When I mentioned an ancient saying by a data center manager about storage “As far as we know we never had an undetected storage error”, a brilliant friend pointed out that it applies to successful security breaches too:
“As far as we know we never had an undetected security breach”