Seenthis
•
 
Identifiants personnels
  • [mot de passe oublié ?]

 
RSS: Fil ☂
tous les messages de Fil ☂

Fil ☂

@fil

geek — fil@rezo.net - https://twitter.com/recifs

http://rezo.net
  • Fil ☂ @fil 24/03/2011 07:30
    1
    @aris
    1

    Iranian hackers obtain fraudulent HTTPS certificates: How close to a Web security meltdown did we get? | Electronic Frontier Foundation
    https://www.eff.org/deeplinks/2011/03/iranian-hackers-obtain-fraudulent-https

    improperly issued certs, which were for extremely high-value domains including google.com, login.yahoo.com and addons.mozilla.org (this last domain could be used to trojan any system that was installing a new Firefox extension, though updates to previously installed extensions have a second layer of protection from XPI signatures). One cert was for “global trustee” — not a domain name. That was probably a malicious CA certificate that could be used to flawlessly impersonate any domain on the Web.

    Comodo also said that the attack came primarily from Iranian IP addresses, and that one of the fraudulent login.yahoo.com certs was briefly deployed on a webserver in Iran.1

    #cyberguerre #iran #crypto

    • #Web security meltdown
    • #Jacob Appelbaum
    • #SSL
    • #Electronic Frontier Foundation
    Fil ☂ @fil
    • ARNO* @arno ART LIBRE 24/03/2011 12:17

      #comodo

      ARNO* @arno ART LIBRE
    • Stéphane Bortzmeyer @stephane CC BY-SA 24/03/2011 12:28

      #X.509 (mauvaise technologie, à jeter en bloc).

      Stéphane Bortzmeyer @stephane CC BY-SA
    Écrire un commentaire

thèmes

  • #crypto
  • #cyberguerre
  • #iran

  • IndustryTerm: Web security meltdown
  • Person: Jacob Appelbaum
  • Technology: SSL
  • Organization: Electronic Frontier Foundation
thématisation automatique par OpenCalais
À propos de Seenthis Propriété intellectuelle Recommandations API