Something about Comodo SSL certificates

1 replies
  • OFF TOPIC
  • |
Iran accused of hack attack to steal fake Comodo SSL certificates

Iran accused of hack attack to steal fake Comodo SSL certificates - IT News from V3.co.uk

I thought this was interesting...

Regards
  • Profile picture of the author seasoned
    THIS part is ominous:

    Secondly, in order for the certificates to be of any use, access to the domain name system infrastructure would have been required.
    It SOUNDS like they got SSL certs for EXISTING systems. Such things would work ONLY if they were placed on the same system OR they managed to change the base key, and tricked visitors computers into going there with a method that would ALSO fool the certificates. That can be done in only two ways:

    1. change all users host files. That is near impossible, especially without cluing some in.
    2. Change the DNS server entries on the systems they use. That is EASY for a federal government, like Iran.

    Steve

    Steve
    {{ DiscussionBoard.errors[3588953].message }}

Trending Topics