After digital certificate hack, Mozilla seeks reassurances

The Firefox maker gives CAs until Sept. 16 to answer questions about security

Following the high-profile hack of DigiNotar, the makers of the Firefox browser are asking issuers of digital certificates to take a hard look at their internal security and to report back in a week.

In emails sent out to digital certificate authorities Thursday, Mozilla Certificate Authority (CA) Certificates Module owner Kathleen Wilson asked CAs such as Symantec and Go Daddy to audit their systems for any possible compromise, confirm that nobody can issue a digital certificate without two-factor authentication, and shore up practices with any third parties that might be able to issue digital certificates using the CA's root key.

Mozilla is giving CAs until Sept. 16 to respond to the email, but the browser maker is not saying what will happen if any of its 54 CAs ignore the request.

Mozilla is also telling the CAs to put "automatic blocks in place for high-profile domain names (including those targeted in the DigiNotar and Comodo attacks this year)," Wilson wrote in the email, which was posted to a Mozilla security discussion forum Thursday morning, Pacific time. "Please further confirm your process for manually verifying such requests, when blocked," she wrote.

By asking for a manual verification, Mozilla is trying to make it harder for anyone to issue a digital certificate for Google.com or Facebook.com, two domains that were targeted in the DigiNotar hack. Whoever pulled off that attack helped someone execute a massive man-in-the-middle attack that may have compromised security for as many as 300,000 Iranian Internet users.

Companies such as DigiNotar issue digital certificates that tell browsers and other Internet programs that the servers that they are dealing with are legitimate -- the real Google.com website, and not some phishing site, for example. If hackers can steal digital certificates and somehow also mess with their victim's network to redirect to fake sites, the attackers can create virtually undetectable phishing attacks.

In the case of the DigiNotar hack, security experts believe that this technique was used to break into Gmail accounts.

This week, the hacker who earlier in the year broke into Comodo, another CA, took credit for the DigiNotar hack and said he'd compromised four other CAs, including GlobalSign. GlobalSign immediately stopped issuing digital certificates and began a security audit.

"Anytime we see a security issue like this that might effect [sic] multiple CAs, you can expect to see us communicating actively and quickly," a Mozilla spokeswoman said Thursday via instant message.

Although the Comodo and DigiNotar hacks have shone light on the CA industry and its security practices, it is still too easy to obtain a digital certificate without any human checking to see if it is a legitimate request, said Comodo CEO Melih Abdulhayoglu in an interview Wednesday. Comodo has revamped its security processes since the March attack, but many other certificate authorities still have work to do, he said. "There are hundreds of Certification Authorities out there with the ability to issue certificates to literally anyone. How are they being protected?"

The industry is unprepared for attacks such as the Comodo and DigiNotar incidents, he added. "You've seen it twice in six months. The industry is not ready. The way the industry operates leaves itself vulnerable."

DigiNotar, which took more than a month to notify Mozilla of this latest hack, has had its root certificate removed from Mozilla's list of trusted CAs. Comodo, however, is still listed.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Join the PC World newsletter!

Error: Please check your email address.

Tags applicationssecuritybrowserssoftwareinternetDigiNotarmozilla

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?