also @ TechSpot: Bill Gates is once again the richest person in the world

Forged security certificate targets Google users

By

On August 30, 2011, 2:53 PM

It has been confirmed that DigiNotar, a SSL certificate authority from the Netherlands issued an Internet security certificate to unknown attackers on July 10th. For over 2 months this certificate would have allowed them to setup fake copies of Google websites that appeared genuine to the majority of users, and collect login information for all of the company's services, including Gmail.

It's still unknown how attackers managed to get the fake google.com security certificate issued. First reports of the scam came from an Iranian web user, who posted the information in a Google help forum, sparking speculation that the Iranian government had been involved in the attack and subsequent release of the security certificate.

Google Chrome's in-built security measures did their part in questioning the authenticity of the certificate, but it is very likely that many others were unaware of the problem. This follows a similar incident earlier in the year when Comodo found itself the victim on a hack, with fake certificates for several high profile companies released under its name. Evidence gathered during the investigation of that attack suggested the attack came from within Iran.

The Electronic Frontier Foundation (EFF) commented that it highlighted fundamental issues with SSL and the authorities such as DigiNotar, who issue certificates. "The certificate authority system was created decades ago in an era when the biggest on-line security concern was thought to be protecting users from having their credit card numbers intercepted by petty criminals," the EFF said. "Today internet users rely on this system to protect their privacy against nation-states. We doubt it can bear this burden."

Google in the meantime has taken steps to block all sites issued with DigiNotar security certificates pending a full investigation. Mozilla has also posted an easy guide to remove the DigiNotar fraudulent SSL certificate from your browser.

, ,

User Comments: 7

Got something to say? Post a comment
  1. Staff

    Better be safe than sorry, I just found that certificate on my Firefox install that I use for work.

  2. I found it on my Firefox too. I followed the directions and got rid of it.

  3. Luckily I don't use Google so I am not worried about it (and there is no DigiNotar certificate on my notebook) . I think Google is doing the right thing with checking all DigiNotar issued certificates.

  4. Found it on my Mac, to remove it for Safari or Chrome you have to open Keychain Access and search for DigiNotar

  5. Wow....i wonder how wide spread this was....i've found it on all my computers.

  6. Got it too and already removed it in FF.

  7. Same here. Crazy it took 2 months to notice it.

Recently commented stories

Post a new comment

Social Login & Guest Posting TechSpot Members
Login here or sign up for free,
it takes about a minute.
Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.
TechSpot on:

Subscribe to TechSpot

Get free exclusive content, learn about new features and breaking tech news.