Home page logo

nanog logo nanog mailing list archives

Re: Verisign deep-hacked. For months.
From: "steve pirk [egrep]" <steve () pirk com>
Date: Sun, 5 Feb 2012 22:55:17 -0800

On Thu, Feb 2, 2012 at 16:42, Zaid Ali <zaid () zaidali com> wrote:

That part is ambiguous at the moment since Verisign has not released
details. Symantec has bought the SSL part of the business and claim that
the SSL acquired network is not compromised. Sounds like lots of
assumptions being drawn.


I am thinking it is related to the Chinese hacking of Gmail accounts in the
fall of 2010. Symantic acquired the SSL business in August 2010. The
hacking could have been in the spring for all we know. Google uses Thwate
as it's CA, but Thwate has "Builtin Object Token: Verisign Class 3 Public
Primary Certificate Authority" as it's root.

Seems to me part of the problem was traced back to browsers not checking
revoked certs via the browser CRLs. Didn't some in the chain have revoked
certs still installed?

steve pirk
"father... the sleeper has awakened..." paul atreides - dune
Google+ pirk.com

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]