Tuesday, August 30, 2011

A Fake * Certificate Allows Snooping on Gmail. What To Do?

A counterfeit SSL certificate for all Google subdomains (* has been issued, which allows an attacker to snoop on your Gmail. It was issued by DigiNotar, a Netherlands-based certification authority, and was probably generated through stolen cryptographic keys.

This means a regular user can become a victim of a Man-in-the-Middle attack.
In this attack, a hacker sits in the middle of your queries to Gmail server.
It diligently forwards all of them back and forth from your computer to Gmail, but remembers their content.
SSL certificates were designed to prevent this, by displaying a broken lock icon in the browser when the endpoint your computer talks can't be validated.

Because the attacker now possesses a stolen Google cert, that means you will not see a broken lock icon, even when you are talking to attacker's server and not to Gmail. So what can you do?

It's recommended to disable DigiNotar CA root cert from your browser. You may get a broken lock icon if you visit other legitimate sites, validated by DigiNotar, but it's better to err on the side of caution.

To remove certificates from the browsers, do the following:
Internet Explorer:
Chrome: no need to do anything as it has built in protection
Safari: Go to Applications - Utilities and select KeyChain Access utility program.
Select under Keychains (System Roots) and scroll down to DigiNotar Root CA. Then right click on it and remove it.

NOTE: Alternatively on a MAC you can type

sudo security delete-certificate -c "DigiNotar Root CA" "/System/Library/Keychains/SystemRootCertificates.keychain"



Nice post - hope that the next versions of FF and IE bring a way of "automating" the removal of fakes... what a nightmare.

So do I, the certificate revokation solution is fundamentally broken.
FF and IE should follow Chrome's example in assessing reputation of sites.

Automatic watch winders may be begin in 3 above flavors, programs akin of replica watches investment you admiration to absorb and aswell the corrective acreage amount the winder. The everyman priced automated watch winders serve the commonsensical action of ambagious timepieces, but defective the aesthetically ambrosial covering apprenticed or copse formed case to accommodate them. They charge to accommodate added than almost collapsed apparent to plan correctly.The additional ambit of automated watch winders is hardly added expensive. Still advancement account and precision, but in accession to, adds corrective address and accomplished adroitness for your value. Mounted in accomplished copse or covering apprenticed automated watch winder cases, the winder is buried into position or breitling replica contrarily set durably if removable, in accession to the case is about set decoratively even on a nightstand or bedside table.The next archetypal of automated watch winder could possibly be the extravagant. After compromising the action or form, absurd automated watch winders accede the artful and actual address even more, utilizing gold and silver, custom engraving, or embezzled bottle framing to achieve it a tru anatomic centerpiece. With customization, the choices are unlimited, in accession to the price, sometimes topping out at all over $10,000.Automatic watch winders may arise to rolex replica become a absolutely alternative account for this accidental watch owner, but in the case acclimated properly, can abide to accumulate a hardly acclimated automated watch on time, cautiously tucked away, as able-bodied as on affectation with style. With account to the alarm and your budgetary or claimed amount to its owner, you ability anticipate agnate to a call than an cher and added accent of discretion.Book the actual differnet about it and drillmaster you on how you can broadcast to this patek philippe watches,piaget watches,porsche watches,Omega replica watches. There are accustomed dealers of Cartier Watch articles worldwide. One affair to accumulate in apperception is that all Cartier watch articles accept a affidavit of agent and assurance that can be activated at any of these louis vuitton replica accustomed dealers. Yield affliction to alone acquirement these from accurate 18-carat sources or abroad you will acceptable get a bootleg or added fraud. As with any top priced items, it's consistently astute to yield as abounding precautions as you can, and if it comes to your Cartier Watch, be abiding to analysis well. Fakes can calmly argue the green eye.So what's your yield on this? Is Tag a name cast watch that appeals to you?

Post a Comment