DigiNotar Certificate Authority Breach Crashes e-Government in the Netherlands
POSTED BY: ROBERT CHARETTE / FRI, SEPTEMBER 09, 2011
Last March, you may remember, the Italian partners (registration authorities) of the certificate authority company Comodo (namely GlobalTrust.it and InstantSSL.it) were hacked and nine Secure Sockets Layer (SSL) encryption certificates fraudulently issued for Google, Microsoft, Skype, and Yahoo, among others. SSL encryption certificates are meant, to quote from VeriSign, the first company to issue SSL's in 1995, to help "... assure customers that they are safe from search to browse to buy and sign-in. When customers see the VeriSign Trust(tm) Seal, they know they can trust the link, trust the site, and trust the transaction." The attack on DigiNotar was detected on the 19th of July the company said in its press release, and it also reported that it had revoked the fraudulent certificates that were issued. Its press release did not say how many certificates had been issued, however, only that one involved Google. However, one certificate was apparently overlooked during the detection process and that one only came to light when the Dutch government informed DigiNotar. But not to worry, government sites were not at risk of being compromised, DigiNotar claimed.
The press release tried to sound upbeat, with VASCO stating that it "... expects the impact of the breach of DigiNotar's SSL and EVSSL [
Extended Validation SSL] business to be minimal." A Dutch IT security company -
Fox-IT BV - was hired to conduct an investigation into the incident, which came to be called internally, "Operation Black Tulip."
However, almost immediately after the public announcement of the breach, it became clear that the attack on DigiNotar might be worse than what the company was letting on. A story appearing in
ComputerWorld soon after DigiNotar's announcement indicated that the fraudulent Google certificate was issued on July 10, over a week before DigiNotar said it had first detected the breach. In addition, a DigiNotar spokesperson admitted to ComputerWorld that "several dozen" certificates had been faked, not just a small number as it previously implied.
By the 3rd of September, it was becoming clear that the IT security situation caused by the breach was indeed becoming dire for some. For on that day, reported the
AP, the Dutch government announced that because of the breach, "
it could not guarantee the security of its own Web sites." In addition, the government said it was taking over DigiNotar's operations, a move the company did not fight against.
Press speculation continued that the hack attack was the work of the Iranian government.
Then on the 4th of September, the news turned even more ominous. A story in ComputerWorld said that the "several dozen" faked certificates actually numbered more than 500 and included ones for "
intelligence services like the CIA, the U.K.'s MI6 and Israel's Mossad." This news caused Google, Microsoft, Mozilla, etc. to move to "untrust" any and all certificates that had been issued by DigiNotar. News also surfaced, said ComputerWorld, that DigiNotar may have been compromised as early as May 2009.
For all intents and purposes, DigiNotar's CA operation was now out of business. So much for VASCO's claim of the breach having little material impact on DigiNotar's business.
On the 5th of September, DigiNotar released an interim report by Fox-IT on its investigation into the Operation Black Tulip attack. The
report (PDF) is not pretty reading (
an overview of the report can be found in this ComputerWorld article). Traces of the attack could be found as early as
the 17th of June, it stated, meaning that it had gone undetected for more than a month. Further, a total of 531 fraudulent certificates were issued for 344 domain names. In addition, it appeared that some 300,000 Gmail accounts - mostly in Iran - had been compromised.
Moreover, DigiNotar's IT security was woefully deficient for its trusted role as a CA. The report said:
"The most critical servers contain malicious software that can normally be detected by anti-virus software. The separation of critical components was not functioning or was not in place. We have strong indications that the CA-servers, although physically very securely placed in a tempest proof environment, were accessible over the network from the management LAN."
"The network has been severely breached. All CA servers were members of one Windows domain, which made it possible to access them all using one obtained user/password combination. The password was not very strong and could easily be brute-forced."
"The software installed on the public web servers was outdated and not patched."
"No antivirus protection was present on the investigated servers."
"An intrusion prevention system is operational. It is not clear at the moment why it didn't block some of the outside web server attacks. No secure central network logging is in place."
The Fox-IT report declined, for obvious reasons, to describe exactly how the attack successfully penetrated DigiNotar.
The news that 300,000 Iranian email accounts had been compromised reinforced the idea that the attack was government-sponsored, and primarily aimed at spying on Iranian dissidents.
At the very least, the attacks against Comodo and now DigiNotar and possibly GlobalSign and several others demonstrates that at least some CA authorities are not nearly as secure as was generally believed.
While Mozilla's actions are yet being publicly followed by Google, Microsoft, etc., I suspect behind the scenes they are exerting their own pressure on CA's to tighten up their security. I wouldn't be surprised to see lawsuits filed against DigiNotar in the near future, either.
The attack also shows what can happen when the trust in the Internet is severely undercut as has happened in the Netherlands.
I'll post updated information on this story as it emerges, especially on the situation in the Netherlands.
+++
Fun stuff to read, tell and watch:
...an Israeli lawyer has filed a class-action lawsuit against former President Jimmy Carter, seeking $5 million in damages because his book "Palestine: Peace Not Apartheid" allegedly defamed Israel. Link:
http://tinyurl.com/3pltqg2
"...when you have laws against questioning the Holocaust narrative, you are screaming at the other person to stop thinking!!!" ---Mike Santomauro. *Anthony Lawson's Holocaust Video "were the Germans so stupid"... Link:
http://tinyurl.com/44nsrco
Peace.
Mike Santomauro
Editorial Director
Call anytime: 917-974-6367