Kwam dit toevallig tegen op een nieuws site, wordt wel leuk zo. Iedereen zot maken dat je een ssl certificaat nodig hebt en dan je eigen servers niet (genoeg) beveiligen.
SSL provider Comodo was hacked allowing attackers to obtain secure certificates for Google, Yahoo, Skype and others. comodo is claiming that the sophisticated attack against its European partner must have been "state-driven." Comodo's own incident report points out IP addresses from Iran responsible for the attack. While simply obtaining these certificates, which have since been disabled, wouldn't make those sites vulnerable -- it would allow passwords and emails to be snooped using man-in-the-middle attacks to impersonate the legitimate sites. That would be pretty trivial to do if, say, you were Iran, which controls the nations telecommunications infrastructure.

Likes:


Quote
