Information Age: News, analysis & insight for IT & business leaders

Hackers target Google users with fake SSL certificate

30 August 2011  

Attempted 'man-in-the-middle' attacks, seemingly aimed at Google users in Iran, exploited false security certificate issued by Dutch CA

Web giant Google has revealed that hackers have been using a fake security certificate to eavesdrop on users based in Iran.

Secure websites prevent hackers from intercepting messages by using SSL (secure sockets layer) certificates. Issued by various certification authorities (CA), these tell the users' browser that a website can be trusted. Fake certificates can be used to trick users' into thinking a malicious site is legitimate or, in a so-called 'man in the middle' attack, to redirect traffic through a malicious site where it can be intercepted or even changed.

Google says that hackers have been using a fake certificate, issued by a Dutch CA called DigiNotar which "should not issue certificates for Google". The CA has since revoked the certificate, and Google, Microsoft and Firefox-maker Mozilla have all issued patches that mean their browsers will no longer trust DigiNotar's certificates.

DigiNotar has not revealed how or why the false certificate was issued. One possibility is that it was hacked itself – this happened to another CA, Comodo, earlier this year. Comodo said at the time that it had been breach by hackers that appeared to originate in Iran.

Iran is one of the countries embroiled in so-called "cyber warfare". Its government says that the US and Israel were behind Stuxnet virus that infected Iranian nuclear control systems last year, while a group called the Iranian Cyber Army has hit pro-US websites and has been accused of involvement in the Comodo attack.

As with all "cyber war" activities, however, it is difficult to ascertain whether the perpertrators are as they seem or are using a politically plausible cover for their actions.


Comments 

There are currently no comments on this article

People who read this also read...

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">