Has ComodoHacker signalled the end of the CA system?
By Tom Brewster,
ANALYSIS A certain pesky web denizen known as ComodoHacker has been causing a commotion recently.
Last week, he/she claimed a hack on Certificate Authority (CA) DigiNotar, resulting in over 500 fake website certificates being issued for big-time services including Gmail and an MI6 website.
Then Belgian CA GlobalSign stopped issuing authentication certificates after ComodoHacker claimed to have gained access to its servers. They also claimed to have broken into three other certificate authorities outside of GlobalSign and DigiNotar.
The hacker has also threatened to use the fraudulent certificates to carry out man in the middle attacks on organisations in Europe, Israel and the US.
I don’t know if this is fixable at all, short of worldwide social changes.
Earlier in the year, another CA known as Comodo was hacked. Can you guess where ComodoHacker got their name?
Outside of the significant cyber war implications, with some saying the DigiNotar hack will have wider connotations than Stuxnet, ComodoHacker has again thrown the whole CA system’s credibility into doubt.
Time for a change
There’s little doubt something needs to change. It no longer seems sensible to carry on placing all our trust in over 650 CAs, with whom the end user never has any direct contact. They are an invisible force and, in some cases, a weak one. Given their whole business is based on trust, the CAs themselves will be feeling more than tetchy about the current situation.
There are many pertinent questions that need to be asked about the security of the CA system.
“How many of them do you know, let alone trust? Should you trust a state-owned CA more than a commercial concern, or should you trust in market forces and vested interests to override political expediency? Where is the global authority with the mandate and the impartiality to authenticate all those CAs? Who would authenticate the authenticators?” said David Harley, senior research fellow at ESET.
“The problems aren’t so much with the technicalities of SSL, as with the difficulties of implementing a system that assumes trust in the provider without a realistic mechanism for determining where you can safely invest that trust.”
Harley wasn’t sure if the system could be fixed at all. We may be stuck with a flawed framework forever.
“I don’t know if this is fixable at all, short of worldwide social changes on the scale of an accelerated continental drift (but in reverse). We’ve arbitrarily decided to invest trust in CAs, and the opportunities for withdrawing that trust (at any rate without the cooperation of the CAs) are severely restricted (i.e. to take it or leave it),” he told IT Pro.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Mesh Network
I keep saying it.. We need a mesh network, not this crappy tree structured network. 1 route means 1 means of authentication, 10 routes means 9 chances for a MITM attack to be recognised and avoided. If multiple routes are chosen when a remote connection is being established, and the routes are analysed, then the likelihood is that the majority (if not all) of these will have the same final end point, or at worst similar final routes. Any that don't correspond to that majority are reported (for further investigation), and subsequently ignored. It's would in essence be just like the convergence model, but without having to trust anyone else. Well, maybe your ISP, but their days (i'm sure) are numbered.
By Ip_aread13a6ed2e on Tuesday Sep 13