Hackers Infiltrate SSL Certificates of CIA, MI6
The theft of online security certificates by hackers thought to be from Iran may be even more serious than first thought. The stolen certificates include those for security agencies from the United States, United Kingdom and Israel.
The security breach originates with DigiNotar, a Netherlands organization that produces Secure Sockets Layer (SSL) certificates which are used by webites. An SSL, for example, is used when home users connect to their banking web sites. Using the SSL certificate, information to and from the home PC to a bank website is encrypted and cannot be intercepted by a third party.
As well as being part of the system that allows encrypted data to travel to and from websites, SSL certificates also confirm whether or not a particular website can be trusted. SSL information is usually displayed in a browser that operates using https:// instead of http://.
More Than 500 Bogus SSL Certificates Created
Unfortunately, an attack on DigiNotar gave hackers the ability to create fraudulent but effective certificates.
At first, DigiNotar revoked the SSL certificates, meaning the fraudulent SSL certificates would not work. It later turned out they had missed one SSL certificate that covered all Google services, and that hackers were using the certificate to go after Google users in Iran.
It now appears that at least 531 bogus certificates were created as a result of the hacking. Not only were certificates issued for most major tech and social networking sites, but the hackers even got certificates for the CIA, Britain's MI6 and Israel's Mossad agency.
Note that bogus security certificates don't allow hackers to directly breach websites of the organizations concerned.
Instead, the certificates make it possible to create a bogus / copycat website that appears genuine to a user's computer. That, in turn, could make it possible to trick users into attempting to login to a bogus website, and essentially hand over their log-in details.
This is what is referred to as "phishing" for sensitive information. The phished data can later be used to guess passwords on other web sites of users, including online banks since it's not uncommon for users to use the same password on more than one website.
The good news is that, despite the bogus and real websites looking completely identical and passing SSL certification, most of the sites do not store sensitive information that would allow a hacker instant access to online funds. (Source: pcworld.com)
Browser Firms Pull Plug on Certificates (Real or Fake)
At first, Google, Microsoft and Mozilla decided to automatically block hundreds of the certificates from being accepted by their browsers, but continued to accept those from Dutch government websites. At the time of writing, both Google and Mozilla are simply blocking any certificate issued by DigiNotar. (Source: computerworld.com)
There's been widespread criticism of DigiNotar's response to the attacks, with claims it was too slow to admit the security breach, even privately, and that it failed to keep track of which certificates had been breached.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.