<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/ssl-certificates" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Ssl-certificates ]]></title>
                <link>https://www.itpro.com/tag/ssl-certificates</link>
        <description><![CDATA[ All the latest ssl-certificates content from the ITPro team ]]></description>
                                    <lastBuildDate>Mon, 07 Mar 2022 11:46:25 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Leaked Nvidia certificates used to sign malware bypassing Windows detection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/365023/nvidia-certificates-sign-malware-bypassing-windows-detection</link>
                                                                            <description>
                            <![CDATA[ Windows admins are advised to implement custom policies to avoid seemingly legitimate malware making its way into corporate environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xdcNJbkZFegVyXtbotJyz9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T3kcYWHsx4f9aTsbZJgEhn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Mar 2022 11:46:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T3kcYWHsx4f9aTsbZJgEhn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Windows logo on a phone in front of a malware warning]]></media:description>                                                            <media:text><![CDATA[The Windows logo on a phone in front of a malware warning]]></media:text>
                                <media:title type="plain"><![CDATA[The Windows logo on a phone in front of a malware warning]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T3kcYWHsx4f9aTsbZJgEhn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered malware being signed with Nvidia code signing certificates days after the LAPSUS$ group <a href="https://www.itpro.com/security/hacking/364068/nvidia-confirms-data-breach-lapsus-leak" data-original-url="https://www.itpro.com/security/hacking/364068/nvidia-confirms-data-breach-lapsus-leak">leaked a trove of the company’s stolen files</a>.</p><p>Part of the stolen files included two code signing certificates and although they’re now expired, signing malware with them will still influence Windows into loading the <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> onto systems.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/364068/nvidia-confirms-data-breach-lapsus-leak" data-original-url="/security/hacking/364068/nvidia-confirms-data-breach-lapsus-leak">Nvidia confirms data breach as hackers make additional demands</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30081/what-is-a-trojan-virus" data-original-url="/security/30081/what-is-a-trojan-virus">What is a Trojan?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a></p></div></div><p><a href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">Windows</a> typically rejects drivers or executables signed using expired certificates. If the certificate was issued after 29 July 2015 then it would require a timestamp - a method of using trusted certificates after expiration - but certificates issued before that date, as in the case of these two Nvidia certificates, Windows will accept them without timestamps, expired or not, <a href="https://twitter.com/BillDemirkapi/status/1499437244830175236?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1499437244830175236%7Ctwgr%5E%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fmalware-now-using-nvidias-stolen-code-signing-certificates%2F">said</a> Bill Demirkapi, offensive security at Zoom. </p><p>Such certificates are used so Windows users can verify the authenticity of any given driver or application. Signing malware with a legitimate, although expired certificate means Windows will be convinced the application is genuine and has not been modified by a third party.</p><p>Among the types of malware already discovered to be signed with Nvidia’s code signing certificates are <a href="https://www.itpro.com/security/34296/hacking-group-fin6-changes-tactics-and-aims-at-e-commerce-websites" data-original-url="https://www.itpro.com/security/34296/hacking-group-fin6-changes-tactics-and-aims-at-e-commerce-websites">Mimikatz</a>, Cobalt Strike beacons, and <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus" data-original-url="https://www.itpro.com/security/30081/what-is-a-trojan-virus">remote access trojans</a>, according to VirusTotal searches.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>"The recent Nvidia security breach involving certificate abuse is eerily like the one Opera suffered in 2013 and one that <a href="https://www.itpro.com/643201/adobe-overhauls-digital-signing-system-post-attack" data-original-url="https://www.itpro.com/643201/adobe-overhauls-digital-signing-system-post-attack">Adobe reported in 2012</a>," said Pratik Selva, senior security engineer at Venafi. "If organisations do not properly secure the process and the infrastructure for managing code signing certificates, the likelihood of abuse, as well as the impact of any compromise, are both extremely high.</p><p>"Although the certificates have expired, Windows will still allow a driver signed by a company to be installed so that it still constitutes a risk," said Alexis Vanden Eijnde, senior security consultant at Prism Infosec. "Microsoft should soon add the certificates to their revocation list and this will prevent the malicious drivers signed by stolen certificates from being loaded into Windows."</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/jkgxniZpDqk" allowfullscreen></iframe></div></div><p>Windows admins are <a href="https://twitter.com/dwizzzleMSFT/status/1499527802382471188">advised</a> to create custom policies in Windows Defender Application Control to filter out the approvals for specific signed certificates.</p><p>The Lapsus hacking group said last week Nvidia had until Friday 4 March 2022 to completely open source its <a href="https://www.itpro.com/hardware/30399/what-is-a-gpu" data-original-url="https://www.itpro.com/hardware/30399/what-is-a-gpu">GPU</a> drivers across all operating systems or the complete collection of stolen files would be leaked online.</p><p>The group has provided few updates since the deadline has passed apart from announcing its second major leak in as many weeks. LAPSUS$ said on Friday that <a href="https://www.itpro.com/security/data-breaches/365022/samsung-hack-190gb-source-code-data" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/365022/samsung-hack-190gb-source-code-data">it obtained an array of source code belonging to Samsung</a> which could lead to access to the “lowest level” of devices such as its Galaxy series of smartphones. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GoDaddy data breach exposes over 1.2 million customer details ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/361624/godaddy-data-breach-exposes-over-12-million-customer-details</link>
                                                                            <description>
                            <![CDATA[ Attacker had access to admin passwords for over two months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oKMep62X2yJqgNyJWkwRq6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5q47ftzYLHRYG2sxVMU47H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Nov 2021 08:44:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5q47ftzYLHRYG2sxVMU47H-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The GoDaddy website displayed inside a magnifying glass hovering over a browser window]]></media:description>                                                            <media:text><![CDATA[The GoDaddy website displayed inside a magnifying glass hovering over a browser window]]></media:text>
                                <media:title type="plain"><![CDATA[The GoDaddy website displayed inside a magnifying glass hovering over a browser window]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5q47ftzYLHRYG2sxVMU47H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hosting company GoDaddy has said that around 1.2 million users have been affected by a data breach on its managed WordPress hosting service.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/361237/wordpress-plugin-exploit-puts-over-90000-sites-at-risk" data-original-url="/security/vulnerability/361237/wordpress-plugin-exploit-puts-over-90000-sites-at-risk">WordPress plugin exploit puts over 90,000 sites at risk</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/355539/godaddy-reports-october-data-breach" data-original-url="/security/data-breaches/355539/godaddy-reports-october-data-breach">GoDaddy admits it fell victim to data breach in October</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/web-browser/359255/wordpress-may-ban-googles-floc-third-party-cookies-alternative" data-original-url="/network-internet/web-browser/359255/wordpress-may-ban-googles-floc-third-party-cookies-alternative">WordPress may ban Google FLoC over security fears</a></p></div></div><p>The hack is said to have exposed email addresses, customer numbers, administrative login credentials, and in some cases SSL private keys.</p><p>The hosting company discovered that an intruder had gained access to its managed WordPress hosting environment on Nov 17, it said in a filing with the SEC. The intruder used a stolen password to access the provisioning system for the service.</p><p>Up to 1.2 million active and former users of the company's managed service had their email addresses and customer numbers exposed, the company said, raising the possibility of further <a href="https://www.itpro.com/security/phishing" data-original-url="https://www.itpro.com/search/phishing">phishing attacks</a> to come. The original administrative passwords for the managed WordPress accounts were also available to the hacker, putting the accounts themselves at risk if the credentials were still in use.</p><p>Also exposed were sFTP and database usernames and passwords, and an undisclosed number of users also had their SSL private keys exposed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QDksvAYJFwkcCugTbPvwS9" name="QDksvAYJFwkcCugTbPvwS9.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" mos="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Protecting every edge to make hackers’ jobs harder, not yours</strong></p><p class="fancy-box__body-text">How to support and secure hybrid architectures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours" data-original-url="/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours">FREE DOWNLOAD</a></p></div></div><p>GoDaddy discovered that the intruder had been inside the system since September 6, meaning that the hacker has had access to the data for over two months. It worked with a forensics company upon discovering the incident, and has taken steps to safeguard its systems, including changing original administrative passwords that were still in use, resetting sFTP and database passwords, and installing new digital certificates for affected customers.</p><p>"We are sincerely sorry for this incident and the concern it causes for our customers," the company said in its filing. "We, GoDaddy leadership and employees, take our responsibility to protect our customers’ data very seriously and never want to let them down. We will learn from this incident and are already taking steps to strengthen our provisioning system with additional layers of protection."</p><p>In 2017, the company revoked thousands of SSL certificates after issuing them without proper checks and authorization. In January 2019, an independent researcher found a vulnerability in its process for handling DNS change requests that enabled hackers to hijack domains and create phishing campaigns. It also notified customers of a hack that exposed SSH login details in the same year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Exchange admin portal taken offline due to expired certificate ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/development/web-development/359654/microsoft-exchange-admin-portal-taken-offline-due-to-forgotten</link>
                                                                            <description>
                            <![CDATA[ This isn't the first time an expired SSL/TLS cert has downed a service ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8Qm8APnV898AJRGuNLjE1E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E8GtJjWv3FkoKLoZHBMPTb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 May 2021 17:56:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/E8GtJjWv3FkoKLoZHBMPTb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SSL security padlock on a URL address bar]]></media:description>                                                            <media:text><![CDATA[SSL security padlock on a URL address bar]]></media:text>
                                <media:title type="plain"><![CDATA[SSL security padlock on a URL address bar]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E8GtJjWv3FkoKLoZHBMPTb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft's Exchange administration portal was offline over the weekend after the company failed to renew an expired SSL/<a href="https://www.itpro.com/network-internet/domain-name-system-dns/356491/tls-telemetry-report" data-original-url="https://www.itpro.com/network-internet/domain-name-system-dns/356491/tls-telemetry-report">TLS</a> certificate.</p><p><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-admin-portal-blocked-by-expired-ssl-certificate"><em>Bleeping Computer</em> reported</a> that Exchange administrators were unable to access the site on Sunday morning. They encountered an error page explaining that their connection was not private. At the time, Qualys Labs reported the certificate associated with the site expired at 8 am Eastern Time on Sunday, but Microsoft has since fixed the problem.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-hosting/27901/godaddy-revokes-thousands-of-ssl-certificates-due-to-code-bug" data-original-url="/cloud-hosting/27901/godaddy-revokes-thousands-of-ssl-certificates-due-to-code-bug">GoDaddy revokes thousands of SSL certificates due to code bug</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/359222/university-of-hertfordshire-hit-by-cyber-attack" data-original-url="/security/cyber-attacks/359222/university-of-hertfordshire-hit-by-cyber-attack">University of Hertfordshire's entire IT system offline after cyber attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/358480/ukri-services-hit-by-ransomware" data-original-url="/security/ransomware/358480/ukri-services-hit-by-ransomware">UKRI services taken offline after ransomware attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/357271/ryuk-ransomware-takes-us-hospitals-offline" data-original-url="/security/ransomware/357271/ryuk-ransomware-takes-us-hospitals-offline">US hospitals forced offline by reported Ryuk ransomware attack</a></p></div></div><p>Twitter user Tzatl <a href="https://twitter.com/Tzatl2/status/1396489300372594698">tweeted</a> at the company on Sunday, asking: "Did you guys really forget to renew a certificate?" Microsoft responded that it had isolated the problem and was applying a fix, referring users to entry EX257883 under its service health dashboard.</p><p>The issue provoked some teasing from users on Twitter. "Someone done goofed," replied one user, along with a picture of the untrusted certificate report from Digicert Cloud Services.</p><p>This isn't the first time a large technology company has downed a service by forgetting to renew a certificate. </p><p>Last month, Epic Games <a href="https://www.epicgames.com/site/en-US/expiration-date-4-6-2021">accidentally allowed</a> a certificate used across many of its internal-facing services to expire. That took account logins offline for many of its most popular games, including Fortnite.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pQK9tpNAUHQPYAjbhB2HLb" name="pQK9tpNAUHQPYAjbhB2HLb.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/pQK9tpNAUHQPYAjbhB2HLb.jpg" mos="https://cdn.mos.cms.futurecdn.net/pQK9tpNAUHQPYAjbhB2HLb.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Enabling operational resiliency with Veritas</strong></p><p class="fancy-box__body-text">Boost your DX goals with data and infrastructure insights</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/359584/enabling-operational-resiliency-with-veritas" data-original-url="/business-strategy/digital-transformation/359584/enabling-operational-resiliency-with-veritas">FREE DOWNLOAD</a></p></div></div><p>In February, Google Voice <a href="https://securityboulevard.com/2021/03/google-voice-outage-expired-tls-certificate-brings-down-yet-another-giant">went offline</a> temporarily after a certificate went out of date. In November, GitHub's home page <a href="https://www.techradar.com/news/github-home-page-down-after-apparent-ssl-fail">went down</a> after a certificate responsible for accessing information from a content distribution network expired. Last August, Spotify let a TLS certificate <a href="https://www.engadget.com/spotify-us-outage-august-2020-130456478.html">lapse</a>, leaving users without music.</p><p>Secure Socket Layer (SSL) has evolved into its successor, Transport Layer Security (TLS). Both are <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">cryptographic</a> protocols that provide secure connections between two endpoints. An SSL/TLS certificate enables a website to prove its identity with a trusted third-party certificate authority (CA).</p><p>Certificate management is likely to become more problematic following a change to certificate longevity last September. Apple, Google, and Mozilla all <a href="https://thehackernews.com/2020/09/ssl-tls-certificate-validity-398.html">imposed</a> a maximum 398-day lifetime on certificates from September 1, 2020 in a bid to limit the time a site can use a compromised certificate. This continues a trend of shortening certificate lifespans, which stood at 60 months in 2012, 39 months in 2015, and 27 months in 2018. </p><p>In its 2021 <a href="https://www.keyfactor.com/state-of-machine-identity-management-2021">State of Machine Identity Management Report</a>, Keyfactor found that 88% of companies had experienced at least one unplanned certificate outage in the prior two years.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is SSL under attack? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24315/why-is-ssl-under-attack</link>
                                                                            <description>
                            <![CDATA[ Don't get sidetracked by a storm in the SSL teacup, warns Davey Winder... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">um51CfJRCneWtdyvNJ2Geh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AXvhkYX2jPxb4ujaUa9UxQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 29 Mar 2015 19:52:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AXvhkYX2jPxb4ujaUa9UxQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SSL secure]]></media:description>                                                            <media:text><![CDATA[SSL secure]]></media:text>
                                <media:title type="plain"><![CDATA[SSL secure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AXvhkYX2jPxb4ujaUa9UxQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SSL is under attack, not just from those who would do bad things unto thee but also from We The Media. The latest headline-grabbing threat was revealed in an <a href="https://www.openssl.org/news/secadv_20150319.txt">OpenSSL security advisory</a> last week which started with a high severity warning entitled "OpenSSL 1.0.2 ClientHello sigalgs DoS (CVE-2015-0291)."</p><p>This could impact users of the open source crypto library, well OpenSSL version 1.0.2 anyway, and to cut a very long and boring story short enable a Denial of Service attack to occur against the server. It enabled a malicious client to crash - and then reboot - the server with a NULL pointer deference when renegotiating with an invalid signature algorithm. I did warn you it was boring. Not, however, as boring as the IT security industry commenting spat that rolled out as a result.</p><p>Here's how these things tend to work: a security scare/advisory/patch is revealed and immediately the IT security vendors and industry players start providing comments to their marketing people who then spin these out to us press folk in the hope that we will use their client quote in a news or analysis piece with a mention of the company at worse and a link to their site or product at best.</p><p>There's nothing wrong in that, per se, and these comment releases can often be the starting point of some very interesting and informative follow up conversations for journalists covering the story. Where things can go a bit pear-shaped, though, is when a company has nothing of value to say, but the PR people spin the release out anyway. The OpenSSL advisory was no exception to the industry comment flood rule, and amongst the inevitable marketing dross there were a few real peaches. Just not, perhaps, for the intended reason.</p><p>On particular expert added to the hype around just how big the vulnerability was - via an embargoed press release to stir up the excitement further. A little while later, that opinion seemed to change to suggest it was preferrable to certain other forms of attack. </p><p>I had to read the statement several times for it to sink in. Could a security outfit really be saying that one attack is preferred to another? This made me wonder whether we should be thinking in terms of preferred vulnerabilities at all. After all, if your organisation was taken out of play by a DDoS attack I'm pretty sure you wouldn't be thinking "phew, that was a close one, it could have been a data breach."</p><p>In the real world of tight budgets and tough choices, there has to be some form of risk analysis to determine where the money should be spent in terms of the data protected and the cost to the organisation if a breach were to occur. However, I'm not sure that this risk auditing should extend to a point of threat granularity whereby you determine that one attack mode is less worthy of prevention than another. Especially as the newly released <a href="http://www.corero.com/DDoS_Trends_Report_Q4_2014">Quarterly DDoS Trends and Analysis Repor</a>t from Corero reveals that, in the case of DDoS, 79 per cent of the attacks it analysed for the research were less than 5Gbps in peak bandwidth utilisation. This suggests they were intended to distract corporate security teams while leaving enough bandwidth for a subsequent network breach attempt. This kind of blended threat, with a merging of attack types, makes it very hard to determine in advance if one vulnerability is less dangerous than another.</p><p>Ultimately, security should be viewed holistically as part of the process of doing business. A proper 360-degree perspective on securing the network and the data moving around within it is what businesses need to strive to achieve.</p><p>I do understand that risk needs to be assessed and budgets directed according to where the greatest risk to the business sits, but this has to be done within the context of a rounded view of the enterprise threatscape and bad actors inhabiting it.</p><p><em>Is your business prepared for new EU cyber security regulations? This whitepaper offers advice, insight and guidance on what to do next. Read it today here. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook warns of new Superfish threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/malware/24101/facebook-warns-of-new-superfish-threat</link>
                                                                            <description>
                            <![CDATA[ The fake security certificate used by the Lenovo-installed adware can be re-used by hackers, says social network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sxy965Et8cSBfUrkvtTGD5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7GvRgVNDgexq7MZ4z2vfVh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Feb 2015 11:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7GvRgVNDgexq7MZ4z2vfVh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hackers]]></media:description>                                                            <media:text><![CDATA[Hackers]]></media:text>
                                <media:title type="plain"><![CDATA[Hackers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7GvRgVNDgexq7MZ4z2vfVh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are easily able to extract the fake security certificate used by Superfish to make their malware even more dangerous, Facebook has warned.</p><p><a href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" target="_blank" data-original-url="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Superfish, the adware program that came pre-installed on Lenovo machines</a>, used a self-signed security certificate, known as a Certificate Authority (CA), to impersonate any SSL-enabled website.</p><p>That means it could trick a user's computer into connecting with a website by offering up its own, insecure CA, rather than the website's own, which a computer must receive to confirm the website is what it claims to be.</p><p>Known as a man-in-the-middle attack, this undermines the security of web browsers and operating systems, because it can see all of a computer user's actions, including banking, email and Facebook activity.</p><p>Lenovo was quick to state it didn't profile or monitor user behaviour, or record user information, and has now stopped shipping devices with the adware pre-installed.</p><p>However, Facebook security researcher Matt Richard warned other threat actors could re-use the Superfish CA on their own applications.</p><p><a href="https://www.facebook.com/notes/protect-the-graph/windows-ssl-interception-gone-wild/1570074729899339" target="_blank">He wrote</a>: "By reusing the same certificate, a bad actor could potentially obtain that CA file and perform "man-in-the-middle" (MITM) attacks on untrusted networks like public Wi-Fi, set up authentic-looking phishing pages, or sign software that makes people vulnerable to other malicious code as they browse the internet.</p><p>"In this case, the certificate used by the Superfish software is relatively easy to extract. Although we are not aware of anyone abusing this certificate in the wild, it's a real risk and would be hard to detect."</p><p>He said the social network has found more than 12 other software applications using the same fake certificate program as Superfish.</p><p>While Facebook is yet to determine the purpose of these applications, some of which appear to be Superfish-esque adware, he said a number of them are suspicious.</p><p>"What all of these applications have in common is that they make people less secure through their use of an easily obtained root CA, they provide little information about the risks of the technology, and in some cases they are difficult to remove," Richard added.</p><p>These applications are also unlikely to keep up with updates to the secure browser HTTPS protocol, meaning there's a risk they could expose private data to network attackers.</p><p>Superfish's fake CA comes from a company called Komodia, and Facebook found a Trojan horse, <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2014-121000-1027-99" target="_blank">known as Trojan.Nurjax</a>, using the Komodia's libraries of software development kits.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OS X Mavericks update to fix major security flaw in Macs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21688/os-x-mavericks-update-to-fix-major-security-flaw-in-macs</link>
                                                                            <description>
                            <![CDATA[ Apple follows iOS 7 update with Mac OS X Mavericks patch to address encryption issues. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">chjqLpnzMcFpH2HQ2xpUEo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mV58aX34L7Aa9PphaSLkDK-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Feb 2014 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/mV58aX34L7Aa9PphaSLkDK-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[apple logo]]></media:description>                                                            <media:text><![CDATA[apple logo]]></media:text>
                                <media:title type="plain"><![CDATA[apple logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mV58aX34L7Aa9PphaSLkDK-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has patched a major security flaw in OS X Mavericks that could allow hackers to intercept users' communications.</p><p>The OS X Mavericks v10.9.2 patch fixes a vulnerability that alters the way Mac devices handle encrypted communications, and means critical checks on the validity of a site's SSL certificate are overlooked when users try to establish a secure connection.</p><p>As a result, users have been warned to take caution when accessing sensitive web content using unsecured wireless networks until they have a chance to download the fix.</p><p>The emergence of the OS X Mavericks v10.9.2 patch comes several days after the consumer electronics giant <a href="http://support.apple.com/kb/HT6147">flagged the existence of the same fault affecting</a> iOS 6 and iOS7 devices.</p><p>At the time, details about a similar flaw in OS X Mavericks began to circulate, but a fix for the issue was only published on Apple's support pages <a target="_blank" href="http://support.apple.com/kb/HT6150">yesterday</a>.</p><p>The update also reportedly includes improvements to Mail, Messages and Safari apps, and also allows Mac users to participate in FaceTime calls.</p><p>In both cases, Apple's security alerts have stopped short of revealing whether the vulnerabilities have been exploited in the wild, or how long the company has been aware of their existence.</p><p>Mark Bower, vice president of infosecurity firm Voltage Security, said Mac users should download the patch as quickly as possible.</p><p>"This is a major bug that puts users' sensitive data, like login credentials, passwords, email and browsing data at risk," said Bower.</p><p>"Users should patch at their earliest opportunity. Until then, users should be very wary of accessing web content that is sensitive, especially on a network that attackers may also be on at the same time which is more often than you might think."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Who to trust after the VeriSign hack? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638701/who-to-trust-after-the-verisign-hack</link>
                                                                            <description>
                            <![CDATA[ Davey Winder questions what data was stolen from VeriSign and wonders why the company hasn't been more forthcoming. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3NGas8dkF9QkQRJmoNFspt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GaQrmw4oXrUQuMDGqAjUtF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Feb 2012 12:57:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GaQrmw4oXrUQuMDGqAjUtF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GaQrmw4oXrUQuMDGqAjUtF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's difficult to know who or what to trust these days.</p><p>Head over to the <a href="https://www.verisign.co.uk" target="_blank" data-original-url="www.verisign.co.uk">VeriSign website</a> and you will be met by the bold claim that the Secure Sockets Layer (SSL) and code signing certificate services business which specialises in online identity and authentication will "build trust every step of the way" so as to ensure that you can "Trust your link. Trust your site. Trust your transaction."</p><p>But just how waterproof are those claims from the company which was acquired by Symantec back in August 2010, especially following the news that <a href="https://www.itpro.com/638677/verisign-admits-2010-hack" target="_blank" data-original-url="https://www.itpro.com/638677/verisign-admits-2010-hack">VeriSign had been hacked</a> "successfully and repeatedly" that year.</p><p>Researchers are already seeing a rise in attacks which target the worldwide infrastructure that supports SSL.</p><p>The finding came thanks to the US law that requires companies to report breaches. A <a href="http://www.reuters.com/article/2012/02/02/us-hacking-verisign-idUSTRE8110Z820120202" target="_blank">Reuters</a> review of a couple of thousand documents contained in a filing by the US Securities and Exchange Commission (SEC) late last year showed VeriSign was hacked repeatedly during 2010 but the senior management team were not informed of the attacks until September 2011.</p><p>In that SEC filing, VeriSign admitted it "faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers." Although VeriSign remained quiet at the time of the filing, and still remains silent to this day as to exactly what information was accessed and what parts of its network was successfully breached, perhaps the most worrying section of the filing is the admission that "given the nature of such attacks, we cannot assure that our remedial actions will be sufficient to thwart future attacks or prevent the future loss of information."</p><p>VeriSign has gone on to make an official statement which insists that after a "thorough analysis of the attacks... we do not believe that the operational integrity of the Domain Name System (DNS) was compromised" and "we have a number of security mechanisms deployed in our network to ensure the integrity of the zone files we publish." This was good to know as nobody wants the DNS to be compromised, but it still didn't reveal what was compromised, only leading to much speculation regarding the integrity of its SSL certificates.</p><p>This should come as no surprise to anyone with an interest in matters of transactional security, as the whole 'is SSL dead?' debate has been raging for quite some time. Indeed, I myself covered this very subject over at our sister publication PC Pro back in May last year when I <a href="http://www.pcpro.co.uk/features/367549/is-online-shopping-security-fundamentally-broken" target="_blank">asked whether online shopping security was fundamentally broken</a>.</p><p>Back then I was asking if the certificate-based trust model used for just about every financial transaction was secure enough in the light of certificate-related breaches such as Stuxnet which included device drivers signed using compromised certificates to give an impression of validity.</p><p>Then there was the hacker who compromised a Comodo reseller and generated a whole bunch of fake SSL certificates as a result. It was more than a week after the breach was discovered that all the major browsers had updated their certificate information to ensure users were not at risk from sites bearing the fake ones. And who recalls the <a href="https://www.itpro.com/635929/mi6-targeted-in-diginotar-hack" target="_blank" data-original-url="https://www.itpro.com/635929/mi6-targeted-in-diginotar-hack">DigiNotar</a> fuss last year with fake certificates issued in order to impersonate Gmail amongst other services?</p><p>Going back even further, in 2008 I reported here at IT Pro about two years of compromised Linux security based around a vulnerability in the Debian OpenSSL cryptographic libraries and in 2009 I was already asking the 'is SSL secure?' question following a demonstration at Black Hat Las Vegas of man-in-the-middle attacks exploiting flaws in SSL to intercept traffic using a null-termination certificate.</p><p>This is something Rob Rachwald, director of security strategy at Imperva, picked up on when he noted "a growing number of web applications are delivered over the HTTPS protocol (HTTP over SSL) with attackers increasingly focusing their attacks against the various components of SSL." Rachwald claimed his researchers are already seeing a rise in attacks which target the worldwide infrastructure that supports SSL.</p><p>Meanwhile, Catalin Cosoi, global research director at security vendor BitDefender, thinks enterprise trust may already be shattered by the VeriSign breach.</p><p>The potential for some nasty security surprises is going to linger for a while.</p><p>"A valid digital signature is a crucial requirement of 64-bit operating systems whenever a critical piece of software tries to install itself. VeriSign is one of the most important enterprise trust authorities in the world, which delivers people safely to more than half the world's websites," Cosoi said.</p><p>"A certificate issued by VeriSign will automatically be accepted by both browsers and operating systems. This kind of incident practically voids all the security provided by 64-bit operating systems."</p><p>Cosoi concluded his statement on the breach disclosure with a worst case scenario, painting a picture of "several phishing attacks with valid certificates that browsers will render as legit" and which would "potentially yield a huge level of data that could be exploited for financial gain."</p><p>But there is one small detail that just about everyone seems to be missing here: there is absolutely no evidence to suggest that the SSL certification network was compromised at all. In fact, it would appear more likely to have escaped intact.</p><p>First of all the SSL certificate and code signing side of the VeriSign business was acquired by Symantec in 2010, at a time when Paul Meijer was director of infrastructure operations. Meijer continues that same role now for Symantec Authentication Services (which includes SSL and PKI amongst others) and is insistent that the authentication networks were not compromised by the breach.</p><p>Meijer said in a <a href="http://www.symantec.com/connect/blogs/how-can-we-be-so-sure" target="_blank">blog post</a> that "at the time the breach occurred, VeriSign was running a separate production network to host the Authentication Services 'Cloud' of SSL, PKI, VIP, and FDS."</p><p>"When the Authentication Services business moved over to Symantec, we continued to employ the practice of this separate production network. This segregation prevents breaches on the corporate network from infecting the production network.</p><p>"Symantec's production network is completely separate from VeriSign's corporate network. Additionally, our development environment also resides on a separate network from the corporate systems network, and is hosted only in a Symantec-owned facility. Finally, the VeriSign root keys, which form the basis of SSL trust, are kept in an offline state and are never accessible on a network."</p><p>I'm not usually one to stand up for Symantec, but on this occasion it would seem that 'what if' fever has infected the media and security vendors alike, when there is nothing to actually suggest SSL certificates have been compromised.</p><p>I am not, for one moment, underplaying the seriousness of the breach. The potential for some nasty security surprises is going to linger for a while. Yet what the media, and anyone with an interest in keeping their data secure, should be doing is not speculating about certificate-based transactional security but rather putting pressure on VeriSign to come clean and tell us what was, as opposed to what was not, hacked.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SSL under threat as flaw exploited ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636304/ssl-under-threat-as-flaw-exploited</link>
                                                                            <description>
                            <![CDATA[ Fears over the security credentials of SSL rise after researchers claim to have found a way to exploit a long-known vulnerability. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JqstbSLd7cayDQQ2LGm7M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/965nTsTET4CkpRPD3NgkvS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Sep 2011 16:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/965nTsTET4CkpRPD3NgkvS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Threat]]></media:description>                                                            <media:text><![CDATA[Threat]]></media:text>
                                <media:title type="plain"><![CDATA[Threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/965nTsTET4CkpRPD3NgkvS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have found a way to exploit a long-known flaw in TLS (Transport Layer Security) that could undermine the security credentials of the <a href="https://www.itpro.com/636040/has-comodohacker-signalled-the-end-of-the-ca-system" target="_blank" data-original-url="https://www.itpro.com/636040/has-comodohacker-signalled-the-end-of-the-ca-system">SSL</a> cryptographic protocol and affect millions of sites.</p><p>The attack methodology, due to be presented by Juliano Rizzo and Thai Duong at the Ekoparty conference this week, targets TLS version 1.0 and SSL 3.0.</p><p>As millions use those protocols to protect certain web transactions, millions of sites could be affected. Major companies, including PayPal and Google, use TLS version 1.0.</p><p>Fixing the vulnerability that BEAST exploits may require a major change to the protocol itself.</p><p>Rizzo and Duong have created a tool called BEAST (Browser Exploit Against SSL/TLS) to attack the AES encryption algorithm used in TLS and SSL.</p><p>BEAST is able to grab and decrypt HTTPS cookies once installed on an end user's browser. This can be achieved either through an iframe injection or by loading the BEAST JavaScript into the target's browser, according to Kaspersky Lab's <a href="https://threatpost.com/en_us/blogs/new-attack-breaks-confidentiality-model-ssl-allows-theft-encrypted-cookies-091611" target="_blank">Threatpost</a>.</p><p>This means the attackers can hijack users' sessions and get all the information they want.</p><p>"While other attacks focus on the authenticity property of SSL, BEAST attacks the confidentiality of the protocol. As far as we know, BEAST implements the first attack that actually decrypts HTTPS requests," Duong said.</p><p>"While fixing the authenticity vulnerabilities may require a new trust model, fixing the vulnerability that BEAST exploits may require a major change to the protocol itself. Actually we have worked with browser and SSL vendors since early May, and every single proposed fix is incompatible with some existing SSL applications."</p><p>Google has reportedly prepared an update for its Chrome browser already to help counter the BEAST.</p><p>Carrying out the attack is not so simple, however. The hacker has to become the man-in-the-middle' to start with.</p><p>"It doesn't mean that anyone can intercept your network traffic and obtain the real data behind it," said Panda Security's Luis Corrons.</p><p>"To be able to do that, first they need to gain access to your browser to inject some JavaScript that will do the work. And of course, if you already have gained access to the computer you can do that or install any kind of Trojan horse."</p><p>Corrons suggested attackers could also set up a Wi-Fi hotspot to snare users.</p><p>"You can create the typical Wi-Fi hotspot, so when anyone connects to it they'll get redirected to the usual welcome page that says thanks for using this service, keep this page open so you can use it for free, click here to start browsing and that's it," he told <em>IT Pro</em>.</p><p>Other security professionals have shown their concern about BEAST and its implications for millions of websites.</p><p>Philip Hoyer, director of strategy solutions at ActivIdentity, called into question the use of SSL.</p><p>"To spell it out: transaction confidentiality based on the SSL TLS V1.0 protocol (the most used still today) is dead," Hoyer said.</p><p>"The only true defense from fraudulent transactions is to sign the transaction or part of the transaction data so that the attacker cannot inject bogus material. This means effectively using a token with a pin pad (software on phone or dedicated hardware token) to enter transaction details or signing the transaction using a public key infrastructure certification."</p><p>The development comes after fears over hacker exploitation of SSL following hacks on certficate authorities (CAs).</p><p>Over 500 fake certificates were issued following a hack on CA DigiNotar, meaning anyone with those fake certificates could dupe end users into believing their internet transactions were being protected by SSL.</p><p><a href="https://www.itpro.com/636244/diginotar-goes-bankrupt-after-hack" target="_blank" data-original-url="https://www.itpro.com/636244/diginotar-goes-bankrupt-after-hack">DigiNotar was declared bankrupt</a> earlier this week.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Has ComodoHacker signalled the end of the CA system? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636040/has-comodohacker-signalled-the-end-of-the-ca-system</link>
                                                                            <description>
                            <![CDATA[ The CA system has come under fire after ComodoHacker causes carnage, but what is the alternative? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ttWPT8jxs9iLRezxtZyqxM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6VHXvAifbkd83hYHE8gAWi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Sep 2011 12:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Workspace]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Google]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6VHXvAifbkd83hYHE8gAWi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker]]></media:description>                                                            <media:text><![CDATA[hacker]]></media:text>
                                <media:title type="plain"><![CDATA[hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6VHXvAifbkd83hYHE8gAWi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ANALYSIS A certain pesky web denizen known as ComodoHacker has been causing a commotion recently.</p><p>Last week, he/she claimed a hack on Certificate Authority (CA) <a href="https://www.itpro.com/635959/iranians-the-target-of-diginotar-hack" target="_blank" data-original-url="https://www.itpro.com/635959/iranians-the-target-of-diginotar-hack">DigiNotar</a>, resulting in over 500 fake website certificates being issued for big-time services including Gmail and an <a href="https://www.itpro.com/635929/mi6-targeted-in-diginotar-hack" target="_blank" data-original-url="https://www.itpro.com/635929/mi6-targeted-in-diginotar-hack">MI6 website</a>.</p><p>Then Belgian CA GlobalSign stopped issuing authentication certificates after ComodoHacker claimed to have gained access to its servers. They also claimed to have broken into three other certificate authorities outside of GlobalSign and DigiNotar.</p><p>The hacker has also threatened to use the fraudulent certificates to carry out man in the middle attacks on organisations in Europe, Israel and the US.</p><p>I don't know if this is fixable at all, short of worldwide social changes.</p><p>Earlier in the year, another CA known as Comodo was hacked. Can you guess where ComodoHacker got their name?</p><p>Outside of the significant cyber war implications, with some saying the DigiNotar hack will have wider connotations than Stuxnet, ComodoHacker has again thrown the whole CA system's credibility into doubt.</p><p>Time for a change</p><p>There's little doubt something needs to change. It no longer seems sensible to carry on placing all our trust in over 650 CAs, with whom the end user never has any direct contact. They are an invisible force and, in some cases, a weak one. Given their whole business is based on trust, the CAs themselves will be feeling more than tetchy about the current situation.</p><p>There are many pertinent questions that need to be asked about the security of the CA system.</p><p>"How many of them do you know, let alone trust? Should you trust a state-owned CA more than a commercial concern, or should you trust in market forces and vested interests to override political expediency? Where is the global authority with the mandate and the impartiality to authenticate all those CAs? Who would authenticate the authenticators?" said David Harley, senior research fellow at ESET.</p><p>"The problems aren't so much with the technicalities of SSL, as with the difficulties of implementing a system that assumes trust in the provider without a realistic mechanism for determining where you can safely invest that trust."</p><p>Harley wasn't sure if the system could be fixed at all. We may be stuck with a flawed framework forever.</p><p>"I don't know if this is fixable at all, short of worldwide social changes on the scale of an accelerated continental drift (but in reverse). We've arbitrarily decided to invest trust in CAs, and the opportunities for withdrawing that trust (at any rate without the cooperation of the CAs) are severely restricted (i.e. to take it or leave it)," he told <em>IT Pro</em>.</p><p>As any IT guy knows, if you can't fix something, replace it. There are alternatives to the CA system. One of the best, at least according to some big names in the security sphere, is researcher Moxie Marlinspike's Convergence model.</p><p>It has been designed to take out the middle men - the CAs - by giving the user greater power. With the Convergence model, users are handed the SSL certificates directly, before asking a number of "trust notaries" to download it too. It then relies on consensus from these notaries to authenticate the web transaction.</p><p>I don't believe it would be appropriate to abandon the use of certificate authorities without a clear idea of what could replace it.</p><p>To add an additional layer of security, the user goes through a proxy notary so they will remain anonymous to the trust notaries. Sounds like a fine idea, no?</p><p>Yet even that model has its limitations. "There are a couple of issues I can see," Harley said.</p><p>"Firstly, it throws responsibility for deciding who to trust back down towards the user, whereas the public always wants technical solutions that will save it having to think for itself. Secondly, it has to fight an entrenched commercial model."</p><p>Nevertheless, it is a viable option. Time will tell how much support it can gain.</p><p>Don't be hasty</p><p>If we are to tear down the CA system, it needs to be approached with caution. With any project, especially those involving IT, an incremental approach is almost always best.</p><p>Some still argue the CAs have a valuable role, they simply need to be more responsible.</p><p>"I don't believe it would be appropriate to abandon the use of certificate authorities without a clear idea of what could replace it. After all, if a criminal gang successfully impersonated the police, few would suggest that we should abolish the police force," said David Emm, senior security researcher at Kaspersky Lab.</p><p>"The key, of course, is trust. And I think a critical feature of this incident is the fact that DigiNotar massively under-played the significance of the breach. If trust in any CA is to be maintained, disclosure of any breach is essential."</p><p>Emm is right in saying CAs need to get their act together. A number have been caught out. If any more fall at the hands of hackers, then the case for an overhaul of the current model will gain yet more momentum.</p><p>For now, the most astute way forward will be in finding the perfect replacement before any radical change is implemented. Right now, the Moxie Marlinspike model offers a real alternative. It should be explored and tested now. If the decline of the CA's reign over web authentication comes, we need to be prepared.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MI6 targeted in DigiNotar hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/635929/mi6-targeted-in-diginotar-hack</link>
                                                                            <description>
                            <![CDATA[ MI6, the CIA and Facebook were all targeted following a hack on certificate authority DigiNotar. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aGVtuprHdgrJjvRCawks4c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ag7R8AyvsMgRwRSAhRf8wJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Sep 2011 11:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ag7R8AyvsMgRwRSAhRf8wJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber war]]></media:description>                                                            <media:text><![CDATA[Cyber war]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber war]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ag7R8AyvsMgRwRSAhRf8wJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK intelligence body MI6 was one of over 500 organisations targeted by hackers who <a href="https://www.itpro.com/635833/certificate-authority-confirms-hack-after-gmail-attack" target="_blank" data-original-url="https://www.itpro.com/635833/certificate-authority-confirms-hack-after-gmail-attack">compromised certificate authority (CA) DigiNotar</a>.</p><p>When DigiNotar confirmed it was hacked last week, it was believed only a handful of fake SSL certificates were issued. A <a href="https://blog.torproject.org/blog/diginotar-damage-disclosure" target="_blank">list</a> from the Dutch Government has shown 531 rogue certificates were actually issued, including one for MI6 website sis.gov.uk.</p><p>Other targeted sites included the CIA, Facebook, Google, Skype, Twitter and WordPress.</p><p>The Dutch Government confirmed it is looking into reports Iran was responsible for the hacks. The Dutch interior ministry said Government websites may not be safe due to the DigiNotar hack, according to the <a href="http://www.telegraph.co.uk/news/worldnews/middleeast/iran/8741172/Iran-accused-of-hacking-Dutch-websites.html" target="_blank">Daily Telegraph</a>.</p><p>The consequences of the attack on DigiNotar will far outweigh those of Stuxnet.</p><p>"The damage sustained to the Dutch Government IT infrastructure is quite significant. A lot of services are no longer available," said Roel Schouwenberg, Kaspersky Lab expert, in a <a href="http://www.securelist.com/en/blog/208193111/Why_Diginotar_may_turn_out_more_important_than_Stuxnet" target="_blank">blog post</a>.</p><p>"Effectively, communications have been disrupted. Because of this, one could make an argument the attack is an act of cyberwar."</p><p>He said any suggestion the Iranian Government was involved was "all speculation" right now.</p><p>"Any kind of hints found in the registered certificates could well be decoys. I remain with my stance that a government operation is the most plausible scenario," he added.</p><p>VASCO Data Security International, DigiNotar's parent company, said on Friday it wanted to work with the Dutch Government on identifying who was responsible.</p><p>"It is our firm belief that cooperating with VASCO is the right decision for the Dutch Government. We are convinced that together we will solve this issue," said Ken Hunt, VASCO's chairman and chief executive (CEO).</p><p>Schouwenberg also called on Apple to revoke affected CAs from its list of trusted services, as other tech giants like Google, Microsoft and Mozilla have done. DigiNotar may not be the only compromised CA "out there," the security expert warned.</p><p>Schouwenberg suggested the DigiNotar attack could be even more significant than the emergence of the highly sophisticated <a href="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet" target="_blank" data-original-url="https://www.itpro.com/627013/stuxnet-the-most-serious-threat-yet">Stuxnet</a> malware.</p><p>"The attack on DigiNotar doesn't rival Stuxnet in terms of sophistication or coordination," he said.</p><p>"However, the consequences of the attack on DigiNotar will far outweigh those of Stuxnet. The attack on DigiNotar will put cyberwar on or near the top of the political agenda of Western governments."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google rolls out SSL search ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/623593/google-rolls-out-ssl-search</link>
                                                                            <description>
                            <![CDATA[ After showing how many wireless networks are vulnerable by infiltrating them, Google has offered to at least keep your web searches safe from prying eyes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nmk3fDkNkVX5wL8RMbWFQL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sd9Ct5Pa6nxjTgygR6ZwVY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 May 2010 11:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin James ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sd9Ct5Pa6nxjTgygR6ZwVY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security button]]></media:description>                                                            <media:text><![CDATA[Security button]]></media:text>
                                <media:title type="plain"><![CDATA[Security button]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sd9Ct5Pa6nxjTgygR6ZwVY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="http://www.google.com" target="blank">Google</a> has added SSL encryption to its search engine to provide an extra layer of privacy to users' web searches.</p><p>Secure Sockets Layer (SSL) scrambles data being transmitted between a user's computer and a server, making it more difficult for third parties to intercept. Google already uses SSL to protect its Gmail and Google Docs services.</p><p>For now, the <a href="https://www.google.com" target="blank">SSL web search</a> which is accessible by typing "https" at the start of the Google search address instead of "http" (with the "s" standing for secure) is in beta and only covers conventional searches, not speciality services such as image, maps or news searches. As such, the links to more specialised searches present along the top of the screen when using the standard service are absent.</p><p>SSL-protected web searches ensure session-wide encryption of both the transmission of search queries and the results returned by Google's servers. When using the service, the Google logo will be modified to include an SSL label and padlock.</p><p>"We think users will appreciate this new option for searching," Google software engineer Evan Roseman wrote <a href="http://googleblog.blogspot.com/2010/05/search-more-securely-with-encrypted.html" target="blank">in a blog post</a>. "It's a helpful addition to users' online privacy and security, and we'll continue to add encryption support for more search offerings."</p><p>However, Roseman warns that one side-effect of the encryption process is that encrypted searches will invariably be slower than conventional queries, though not significantly so.</p><p>The move is a direct response to the <a href="https://www.itpro.com/637387/google-offers-opt-out-for-street-view-wi-fi-tracking" data-original-url="https://www.itpro.com/637387/google-offers-opt-out-for-street-view-wi-fi-tracking">privacy storm</a> that has engulfed Google over the past week after it emerged that its Street View vehicles had been capturing not only images from around the world for the mapping service, but also any personal data they happened to came across on unprotected Wi-Fi networks.</p><p>In total, more than 600GB of data was collected over a period of three years including emails, passwords and browsing histories. However, Google's claims that beefing up its search engine is a response to "how publicly accessible open, non-password-protected Wi-Fi networks are today" is unlikely to divert much attention from its actions in infiltrating those networks in the first place.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Major SSL encryption flaw hits the web ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/617293/major-ssl-encryption-flaw-hits-the-web</link>
                                                                            <description>
                            <![CDATA[ Tech companies using SSL have some serious work to do to fix a big hole that could leave internet users at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sXqnfrQumwYR1ARTaHLtdT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AXvhkYX2jPxb4ujaUa9UxQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Nov 2009 15:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Asavin Wattanajantra ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AXvhkYX2jPxb4ujaUa9UxQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SSL secure]]></media:description>                                                            <media:text><![CDATA[SSL secure]]></media:text>
                                <media:title type="plain"><![CDATA[SSL secure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AXvhkYX2jPxb4ujaUa9UxQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A major' vulnerability in <a href="https://www.itpro.com/609932/website-danger-as-hacker-breaks-ssl-encryption" target="_blank" data-original-url="https://www.itpro.com/609932/website-danger-as-hacker-breaks-ssl-encryption">SSL</a> (Secure Sockets Layer) authentication has been discovered, potentially leaving web surfers under serious threat.</p><p>The authentication gap allows an attacker to perform a man-in-the-middle' attack, according to security researchers at PhoneFactor.</p><p>PhoneFactor claimed that most websites using SSL encryption were affected, including <a href="https://www.itpro.com/610267/online-banking-fraud-rises-by-132-per-cent" target="_blank" data-original-url="https://www.itpro.com/610267/online-banking-fraud-rises-by-132-per-cent">online banking</a> and <a href="https://www.itpro.com/614239/focus-on-retail-technology" target="_blank" data-original-url="https://www.itpro.com/614239/focus-on-retail-technology">retail</a> sites. Some mail and database servers were also vulnerable.</p><p>It also invalidated the SSL lock, which is used to verify whether website communications are secure.</p><p>Researchers Marsh Ray and Steve Dispensa are believed to have shown the flaw to a working group of affected vendors, which included Microsoft, Intel, Nokia, IBM, Cisco and Juniper.</p><p>In a statement, PhoneFactor said: "[We] volunteered to delay disclosure on the vulnerability until early 2010 to allow time for vendors to make the necessary patches available."</p><p>"However, an independent researcher discovered the vulnerability and posted it to Internet Engineering Task Force (IETF) mailing list on November 4th... News of the vulnerability quickly spread through the IT security community," it added.</p><p>PhoneFactor added that this was a protocol vulnerability rather than an implementation flaw, so the impact was far reaching.</p><p>"All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products," the firm said.</p><p>"Most users will eventually need to update any software that uses SSL."</p><p>Andrew Clarke, senior vice president for Lumension, said in a statement that the SSL flaw was likely to bring a large number of patches in the near term from vulnerable vendors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>