Firm points finger at Iran for SSL certificate theft
Bogus certificates obtained for Google, Microsoft, Skype and Yahoo sites
Computerworld - Iran may have been involved in an attack that resulted in hackers acquiring bogus digital certificates for some of the Web's biggest sites, including Google and Gmail, Microsoft, Skype and Yahoo, a certificate issuing firm said today.
The bogus certificates -- which are used to prove that a site is legitimate -- were acquired by attackers last week when they used a valid username and password to access an affiliate of Comodo, which issues SSL certificates through its UserTrust arm.
Today, Comodo's CEO said his company believes the attack was state-sponsored and pointed a finger at Iran.
"We believe these are politically motivated, state driven/funded attacks," said Melih Abdulhayoglu, the CEO and founder of Comodo, a Jersey City, N.J.-based security company that is also allowed to issue site certificates.
"One of the origins of the attack that we experienced is from Iran," Abdulhayoglu said in an online statement. "What is being obtained would enable the perpetrator to intercept Web-based email/communication and the only way this could be done is if the perpetrator had access to the country's DNS infrastructure (and we believe it might be the case here)."
Comodo's security blog offered more details of the Iranian connection and claimed that at least two Iranian IP addresses and one ISP were involved.
"The IP address of the initial attack ... has been determined to be assigned to an ISP in Iran," said Comodo. "A Web survey revealed one of the certificates [was] deployed on another IP address assigned to an Iranian ISP."
That server went offline shortly after Comodo revoked the certificates.
Fake certificates can be used by attackers to fool users into thinking that they're at a legitimate site when in reality they're not, said Andrew Storms, director of security operations at nCircle Security.
"They would be used in a 'man in the middle' kind of attack," said Storms. "They could use [the bogus certificates] to host a site that looks like one of these real sites, then capture people's log-ins."
Comodo echoed Storms' take on the attack's implication but speculated that it was a government-backed effort.
"It does not escape [our] notice that the domains targeted would be of greatest use to a government attempting surveillance of Internet use by dissident groups," Comodo said. "The attack comes at a time when many countries in North Africa and the [Persian] Gulf region are facing popular protests."
According to a Microsoft security advisory published earlier today, the nine fake certificates were issued for login.live.com, mail.google.com, www.google.com, login.yahoo.com, login.skype.com, addons.mozilla.org and Global Trustee.
- Single-Vendor Security Ecosystems Offer Concrete Benefits Over Point Solutions IT security decision-makers from companies with 100 to 5,000 employees evaluates the current endpoint security solution market based on Forrester's own market data,...
- Case Study: Intuit Turns to Self-Service IT Intuit empowered its users to resolve their own IT issues with a consumer-like experience to free IT to focus on more strategic initiatives....
- Automation for a Better Tomorrow Check out the five most common annoyances facing enterprise IT service desks today, and how automation can resolve all of them. Download the...
- Beyond the Enterprise App Store Leverage proactive, secure and automated IT Service delivery to move beyond the traditional App Store and empower your users. Read the white paper...
- Business-driven data protection Setting up data protection infrastructures with your organizations' core mission or business in mind is key. In this webinar, the ARCserve team will...
- On-Demand Webinar: Mind the Gap! Watch the webinar featuring Bob Janssen, CTO and Co-Founder of RES Software, to start building a solid foundation for business and IT to... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!