09 September 2011

How StartCom Foiled Comodohacker: 4 Lessons | #diginotar #ssl #ca

Strategic Security Survey: Global Threat, Local Pain (click image for larger view and for full slideshow) Based on the boasts of "Comodohacker," he's compromised six certificate authorities (CAs) this year, including Comodo in March and DigiNotar in July. He's also claimed to have exploited at least four more, including GlobalSign.


But the Comodohacker also said that he was unable to hack into StartCom Certification Authority, despite managing to access its network and a hardware security module (HSM). "I already connected to their HSM, got access to their HSM, sent my request, but lucky Eddy . . . was sitting behind HSM and was doing manual verification," according to a Comodohacker post.


Read full article: http://bit.ly/ooAB9I

No comments: