Microsoft blacklists all DigiNotar certificates

By Julie Bort, Network World |  Security Add a new comment

Microsoft on Tuesday blacklisted all DigiNotar certificates after seeing active attacks from at least one fraudulent digital certificate issued by DigiNotar. The company has released updates for all versions of Windows with the new blacklisted data.

DigiNotar is a certification authority that is a member of the Trusted Root Certification Authorities Store. Last week, Dutch authorities and others revealed that hackers had perpetrated a massive theft of more than 500 SSL certificates in July, including several that could attempt to impersonate Microsoft's update services.

BACKGROUND: Comodo hacker claims credit for DigiNotar attack

"Based on our investigation, we've deemed all DigiNotar certificates to be untrustworthy and have moved them to the Untrusted Certificate Store," wrote Dave Forstrom, director of trustworthy computing, on the Microsoft Security Response Center blog. "Additionally, we have extended our support with this update so all customers using Windows XP, Windows Server 2003, and all Windows supported third-party applications are protected."

With 500 spoofed certificates "pwn'd" by the bad guys, Microsoft wasn't the only vendor affected. Last week the TOR Project site, also affected, released a list of all the affected websites in a blog post, and all of the CAs it found to be hosting the hacked certificates. DigiNotar released fake certificates that affected websites and services from Google, Skype, the CIA, Yahoo, Twitter, TOR, Facebook, WordPress, Windows Live, Mozilla and a number of others.

Microsoft, Google and Mozilla all acted quickly to revoke the spoofed certificates so their browsers would reject them. On Sunday, Microsoft assured its customers that the spoofed Microsoft Update certificates could not be used to install malware through Windows Update.

"Attackers are not able to leverage a fraudulent Windows Update certificate to install malware via the Windows Update servers," said Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), in a Sunday blog post. "The Windows Update client will only install binary payloads signed by the actual Microsoft root certificate, which is issued and secured by Microsoft."

Seven of the 531 fraudulent certificates were for Microsoft-related domains including update.microsoft.com and windowsupdate.com, while another six were for *.microsoft.com, and another 17 were for live.com, Microsoft's Windows Live social network and collaboration site.

Microsoft recommends that enterprise users not using Microsoft's automatic updating service immediately install the updates. This includes a rare update for Windows Server 2008 Server Core, which is also affected.

However, more industrywide action may be needed, and Microsoft says it "has been actively collaborating with certificate authorities, governments, and software vendors to help protect our mutual customers."

This is because "the most egregious certs issued were for *.*.com and *.*.org while certificates for Windows Update and certificates for other hosts are of limited harm by comparison," according to the TOR Project blog. "The attackers also issued certificates in the names of other certificate authorities such as 'VeriSign Root CA' and 'Thawte Root CA' as we witnessed with ComodoGate, although we cannot determine whether they succeeded in creating any intermediate CA certs."


Originally published on Network World |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question