AfterDawn: Tech news

Iran blamed for net security attack

Written by James Delahunty @ 25 Mar 2011 8:51 User comments (1)

Iran blamed for net security attack

The finger of blame is being pointed at Iran in what's being called a state-driven attack on Internet security.
Attackers managed to trick a HTTPS/TLS Certificate Authority into issuing fraudulent certificates. The improperly issued certs covered high-value domains including google.com, login.yahoo.com and addons.mozilla.org. One cert was for "global trustee" which could have enabled the impersonation of any domain on the web.

The CA involved, Comodo, said that one fraudulent login.yahoo.com cert was briefly deployed on an Iranian server. The attack on Comodo came primarily from IP addresses from Iran.

The system attacked acts as a guarantee of identity for some of the world's most popular web services. The certificate acts as a digital passport which is checked by the web browser in use. Most browsers have since been updated to detect the use of the bogus certificates to protect users. An obtained fraudulent certificate could aid in impersonating a popular web service on a malicious server.



Comodo said the attack exhibited "clinical accuracy" and added it was likely to be a state-driven attack. Since it came from Iranian sources and appears to have targeted mainly web communications services, it is thought to have been carried out at the request of Iranian authorities in pursuit of opposition groups in the country that use the web to coordinate their activities on the ground.

The incident has raised questions about web security in general. An article on the Electronic Frontier Foundation's website is worth a read.

Tags: Iran
Previous Next  

1 user comment

126.3.2011 04:25

Mozilla admits to mishandling Comodo disclosure....
http://goo.gl/fb/V33fX

Microsoft Shuts off HTTPS in Hotmail for Over a Dozen Countries:
http://goo.gl/fb/1RpLu

This message has been edited since its posting. Latest edit was made on 26 Mar 2011 @ 4:45

Comments have been disabled for this article.

Latest news

Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.
OpenAI shuts down its AI video service Sora OpenAI shuts down its AI video service Sora (24 Mar 2026 6:28)
OpenAI has decided to shut down Sora, its AI video creator, just months after its release. The decision is due to issues such as copyright problems and the deepfake phenomenon.

News archive