Skip to main content

Thread: Iran May Have Acquired Google SSL Certificate, Prompts Browser Security Alerts


http://www.conceivablytech.com/9157/...ecurity-alerts

chrome reportedly able detect fraudulent certificate whey recent security update in browser , confirm vulnerability. google informed mozilla , microsoft both issued security updates products. mozilla revoked certificate, said extent of problem not clear , has therefore published “new versions of firefox desktop (3.6.21, 6.0.1, 7, 8, , 9) , mobile (6.0.1, 7, 8, , 9), thunderbird (3.1.13, , 6.0.1) , seamonkey (2.3.2) shortly revoke trust in diginotar root , protect users attack.”

users urged update browsers.
deleting diginotar ca certificate

http://blog.mozilla.com/security/201...m-certificate/

issue

mozilla informed today issuance of @ least 1 fraudulent ssl certificate public websites belonging google, inc. not firefox-specific issue, , certificate has been revoked issuer, diginotar. should protect users.

impact users

users on compromised network directed sites using fraudulent certificate , mistake them legitimate sites. deceive them revealing personal information such usernames , passwords. may deceive users downloading malware if believe it’s coming trusted site. have received reports of these certificates being used in wild.

status

because extent of mis-issuance not clear, releasing new versions of firefox desktop (3.6.21, 6.0.1, 7, 8, , 9) , mobile (6.0.1, 7, 8, , 9), thunderbird (3.1.13, , 6.0.1) , seamonkey (2.3.2) shortly revoke trust in diginotar root , protect users attack. encourage users keep software up-to-date regularly applying security updates. users can manually disable diginotar root through firefox preferences.
credit

issue reported google, inc.

http://weblogs.mozillazine.org/gerv/...notificat.html

a dutch ca called diginotar has suffered security breach. mozilla removing trust root certificate - hope release updates today. have used eff ssl observatory data make list of affected websites (those certificates chain diginotar root[0]). want warn webmasters of these sites need new certificates asap. , that's use power of community

if can read dutch, appreciate help. there google docs spreadsheet list of affected sites , instructions on how find webmaster email or contact form , warn them, using letter have written. more warning get, less disrupted dutch ssl internet be. please head on there , out thanks!

huh


Forum The Ubuntu Forum Community Ubuntu Community Discussions The Cafe Iran May Have Acquired Google SSL Certificate, Prompts Browser Security Alerts


Ubuntu

Comments

Popular posts from this blog

Warning, the Safe Path is not accessible vm3 - Joomla! Forum - community, help and support

2.5.28 to 3.4.1---Download of update package failed - Joomla! Forum - community, help and support

Your host needs to use PHP 5.3.10 or higher to run this vers - Joomla! Forum - community, help and support