Hackers steal SSL certificates for CIA, MI6, Mossad

By Greg Keizer
Computer World
September 5, 2011

The tally of digital certificates stolen from a Dutch company in July has exploded to more than 500, including ones for intelligence services like the CIA, the U.K.’s MI6 and Israel’s Mossad, a Mozilla developer said Sunday.

The confirmed count of fraudulently-issued SSL (secure socket layer) certificates now stands at 531, said Gervase Markham, a Mozilla developer who is part of the team that has been working to modify Firefox to blocks all sites signed with the purloined certificates.

Among the affected domains, said Markham, are those for the CIA, MI6, Mossad, Microsoft, Yahoo, Skype, Facebook, Twitter and Microsoft’s Windows Update service.

“Now that someone (presumably from Iran) has obtained a legit HTTPS cert for CIA.gov, I wonder if the US gov will pay attention to this mess,” Christopher Soghoian, a Washington D.C.-based researcher noted for his work on online privacy, said in a tweet Saturday.

Soghoian was referring to assumptions by many experts that Iranian hackers, perhaps supported by that country’s government, were behind the attack. Google has pointed fingers at Iran, saying that attacks using an ill-gotten certificate for google.com had targeted Iranian users.

All the certificates were issued by DigiNotar, a Dutch issuing firm that last week admitted its network had been hacked in July.

Read full article here

Fresh food that lasts from eFoodsDirect (AD)






 
Print this page.

Comment Rules


17 Responses to “Hackers steal SSL certificates for CIA, MI6, Mossad”

  1. The only use for these is if somewhere on the net you can spoil DNS cache to make cia.gov or some other site redirect to an IP controlled by you and direct someone to your server. This flaw was corrected years ago. The other way is to won the ISP and resolve these to bogus IP’s not something a hacker is going to have access to.

    You’ll notice Wikileaks SSL cert has been revoked and as a result firefox will not allow you to look at their archives.

    It would seem this is just a way to manipulate browser developers forcing them to stop users rather that just issue a warning. Chrome does the same thing now.

    In the new digital order, you’ll need to be in the green zone to have anything secured. You can self sign certificates and update the browser to store you as a root authority, surely this is next.

  2. The fact that the guy is basically saying ‘the CIA doesnt seem to care”… interesting.. probably them doing all this.

  3. WWIII coming to ur country soon

  4. yea this has the CIA written all over it.

  5. The intel ship is a lot leakier than people think. If the SSL’s were channeled through a single entity then they can be traced and cross reference code compared and selectively removed from https sites.

    What is not making sense about this is that it is being stated that they were stolen in the first paragraph in a batch over 500 and then fraudulently issued. These SSL’s would all have tracers encrypted on them.

    By now this matter should be history because they came from the same source. Something is wrong with this picture. I strongly suspect this was another Mossad job done then targeted Iran as the culprit. The Mossad are able to duplicate any SSL. I am not buying the whole IRAN DID IT THING. NICE TRY MOSSAD STUDENTS, why don’t you get a life and stop picking on Iran. Some fresh air would do you guys a lot of good. Remember the STUXNET… we all know who did that one.

    • Yep, sounds like it is just a smear campaign — in the style of “the dog in the manger”. Could it just be part of the campaign ‘the cannibals’ of the death machine are perpetrating so they can waste more money on the death and destruction waste-it-all industry. I can her the dog-stupid-morons barking for more military spending waste. The parasites are out of control, and don’t really give a shit about humanity. The military industry are the shallowest form of life going — they feed of death, like cannibals. Oh, but America enjoys lording it over others doesn’t it — cause it is infested with British-Zionist Agents of death. They all suck devil shit — the war mongering swine.

      • They are running amok and completely out of control. Due to the fact that the United States of America currently has no President except for the neurolinguistic, MK Ultra CIA groomed Kenyan bot Barry Soetoro who is the pretend President and is thoroughly and completely without Constitutional Jurisdiction over this nation. The office is vacant and being filled with sewage compounded with toxins and parasites who think they can get away with anything they like. It is time for the top military who are still loyal to this nation to physically eject him and his wife Imelda oh I mean Michelle and flush the place out. If David Patreus sitting in the CIA is happy with this scenario then he has lost his excellent mind. He has allowed his alleged African Muslim commander in chief to demean him to the core. I guess Patreus is happy to be a lacky. What is the problem General? Think you are to old to author a new counterinsurgency strategy… we can wait it out a little longer but it is your ball to call.

  6. hackers identify themself as the police and use the identity of some police man they hacked up, then make phone calls identifying themselfs as the police then get people to give them their money or something

  7. “Presumably from Iran” my ass!! It’s prolly someone right in Langley.

  8. Oh boy now the piece of dung federal government really has an excuse to wage some new wars. I bet the CIA is behind this trying to blame Iran. F**k the CIA.

  9. P R E S U M A B L Y F R O M I R A N!!! Yeah….F**king right! God knows it wouldn’t be the Zionists in Israhell!!

    • With their “backdoor” into every ill-gotten PROMIS software that they stole from the American author.

  10. INSIDE JOB! MCB

    • It is getting a little repetitive. Inside Job. Meanwhile everything is being outsourced to the rest of the globe. What funny times we live in.

  11. Oh, Sweet, now the war spreads into the Internet with the speed of computers.

    And we still don’t have any definitive intelligence on who perpetrated 9/11. Spinning reality is getting easier by the minute.

    • I take issue with standardissue: there is definitive intelligence on who perped 911, if the dots seen are connected in the appropriate fashion.

    • Yes we know precisely and definitively who carried out 911 and precisely what happened. The Smoke and Mirrors gig is over. Now it is time to put them all on trial and not let them walk away. Do you want your country to allow mass murderers who profited by trillions of dollars to walk away free as a bird? The problem is that everyone is thinking they are some kind of expert.. well why don’t you leave it to the heavies who are willing to put their life on the line for this nation and are making every attempt to bring back its soul.

      It is amusing to see that suddenly everyone thinks they are trained intelligence analysts. Jumping to hasty conclusions like leap frogs. It really has a pathetic humor to it, it really does.

Leave a Reply

You must be logged in to post a comment.

You can skip to the end and leave a response. Pinging is currently not allowed.

Leave a Reply

Powered by WordPress | Designed by: Premium WordPress Themes | Thanks to Themes Gallery, Bromoney and Wordpress Themes