Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 16, 2012, 04:00:39 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
594594
Posts
63096
Topics
134535
Members
Latest Member:
huskyclaw
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
General Discussion (off topic) Anything and everything...
VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies (Read 16146 times)
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
on:
June 22, 2010, 06:29:39 PM »
Verisign SSL hackable - Comodo exposes, Verisign denies
This is so sad.
The way Verisign dealt with this so irresponsibly is so very sad.
I do wish they had simply acknolwedged the vulnerability to us in private, we would have been more than happy to work with them on this.
There are simply no winners when things get this messy. Everyone is a loser, Verisign, Comodo and Verisign' customers. Shame....very irresponsible way of dealing with the issue..
And on the background I heard that Verisign has already changed their Server configuration to stop Google from Indexing it.....yet they deny there was anything wrong.....If there was nothing wrong, as they claimed, why are they changing server configuration now?
Verisign
«
Last Edit: June 23, 2010, 04:03:13 PM by Melih
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1706
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #1 on:
June 22, 2010, 07:40:55 PM »
Quote
VeriSign responded, "We thank you for bringing this to our attention, but the information you have accessed is public information that can be found in a multitude of ways
Yeah, but that public information is a VeriSign customer account of a major financial institution can be easily accessed without authentication
It sounds like Verisign is trying to play down the problem
«
Last Edit: June 22, 2010, 07:50:36 PM by jay2007tech
»
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #2 on:
June 22, 2010, 08:19:49 PM »
Quote from: jay2007tech on June 22, 2010, 07:40:55 PM
Yeah, but that public information is a VeriSign customer account of a major financial institution can be easily accessed without authentication
It sounds like Verisign is trying to play down the problem
they are indeed!
If they go fix it while playing it down will make them look untrustworthy.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 3349
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #3 on:
June 22, 2010, 09:17:09 PM »
Is this response given here incorrect?
https://blogs.verisign.com/ssl-blog/2010/06/incorrect_reports_of_verisign.php
It actually sounds reasonable to me. Where am I wrong in my thinking?
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1706
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #4 on:
June 22, 2010, 09:17:51 PM »
(Example)
That's like me being able to find a way to hack into Citibank, then reports it to verisign. They play down the situation (like it's not a big deal), but I'm willing to bet that Citibank thinks it's a big deal
If Verisign DENIES and/or DOESN'T fix it for Major financial institutions, can you imagine how verisign handles there small businesses or home users accounts!!!!!!!!
Quote
Q. Are there actually major security vulnerabilities in VeriSign SSL products that were revealed to the public by Comodo today?
A. No.
That's because comodo didn't release it to the public(In the wild), they used a third-party to tell Verisign the problem.
Quote
Q. Was there any breach? Was any sensitive information or the security of any site, server, enterprise, or certificate compromised in any way?
A. No.
That's because comodo reported it before some hacker figured it.
«
Last Edit: June 22, 2010, 09:37:56 PM by jay2007tech
»
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 3349
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #5 on:
June 22, 2010, 09:23:18 PM »
Quote from: jay2007tech on June 22, 2010, 09:17:51 PM
After looking on line, it seems Verisign got bought out by Symantec (makers of nortan)
Yes they were.
Quote from: jay2007tech on June 22, 2010, 09:17:51 PM
(Example)
That's like me being able to find a way to hack into Citibank, then reports it to verisign. They play down the situation (like it's not a big deal), but I'm willing to bet that Citibank thinks it's a big deal.
I think I see the point. Is it that Comodo was able to (remotely) access information that was supposed to only be publicly accessible from within the specific corporation?
From the article I linked to and Melih's article this appears to be the situation. Is this accurate?
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #6 on:
June 22, 2010, 09:32:21 PM »
We now have no choice but to reveal this info we provided to Verisign. Afterall they don't think its a vulnerability. So I guess its ok for us to reveal it.
PLEASE NOTE: THIS POST IS WRITTEN ONLY AND ONLY AFTER VERISIGN PUBLICLY DECLARED THEY HAVE NO VULNERABILITY AND WHAT COMODO REPORTED IS NOT A VULNERABILITY ACCORDING TO VERISIGN, HENCE WHATEVER IS CONTAINED HEREWITH CANNOT BE CONSIDERED DAMAGING TO VERISIGN OR ITS CUSTOMERS BY VERISIGN'S ADMISSION.
Verisign put themselves in a very difficult position by denying this is a vulnerability. Let me explain why.
If they don't fix the issue
, then they will continue to run an infrastructure that has its weakest link as this password/passphrase. (And I can't believe that banks who fall under FDIC guidelines could possibly operate their operations with this kind of infrastructure, while they are required to have 2 factor authentication for their own customers)
If they fix the issue
, then they will look pretty stupid for denying it in the first place!
Verisign, the choice is yours
The attached document is what was provided to Verisign last week. And they were told about our timescales (we told them we would do it on Monday via email).
PS: Tim Callan wrongly interprets guidelines. If Verisign accepted there was a vulnerability, then Comodo would work with Verisign in making sure it was addressed, without going public. Because Verisign denied that it was vulnerability, that left Comodo with no alternative but to go public. Disclosure guidelines relate to Vulnerabilities that both parties acknowledge, It is very difficult to fix a vulnerability if the vendor does not admit it is a vulnerability. As far as Verisign is concerned it was not a vulnerability, hence his point about disclosure guidelines is simply wrong!
Melih
«
Last Edit: June 22, 2010, 11:28:46 PM by panic
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
SpeedyPC
Comodo's Hero
Offline
Posts: 406
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #7 on:
June 23, 2010, 12:21:15 AM »
What I can say about Verisign in two words B
LL S
T!
Logged
XP Pro SP3 32bit, Avast! Free 7.0.1426, Outpost Firewall Pro 7.5.2, Firefox 12.0 (NS/AdP/WOT/TL/BP/Ghost), Thunderbird 12.0.1 (AdP), SpywareBlaster, HostsMan + MVPS, MBAM, WinPatrol, Hitman Pro, CCE, Panda USB Vaccine, Secunia PSI, CCleaner, PB&R Adv. Free 2011, NortonDNS
patrice58
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 604
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #8 on:
June 23, 2010, 04:29:43 AM »
In Tim Callan's blog here
https://blogs.verisign.com/ssl-blog/2010/06/incorrect_reports_of_verisign.php
one good point was made which was. Q. Why was Comodo searching for vulnerabilities in VeriSign SSL products?
A. We don't know.
Nor do I so why?
Ah ok fair enough.
«
Last Edit: June 24, 2010, 05:06:27 AM by patrice58
»
Logged
Vista Home Premium 32 bit (user account) CISC 4.1.150349.920 + CAV (On Access) + Sandbox,V-Engine 2.7.0.37, SpywareBlaster 4.3, SAS (free), a-squared (free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only), Zemana AntiLogger 1.9.2.206,
burebista
Comodo's Hero
Offline
Posts: 599
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #9 on:
June 23, 2010, 04:55:25 AM »
Quote from: patrice58 on June 23, 2010, 04:29:43 AM
Nor do I so why?
Creating Trust Online™
Does it matter why? For me it looks more important that they discovered something instead asking why choose VeriSign to check.
Logged
If it ain't broke... fix it until it is.
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #10 on:
June 23, 2010, 06:21:05 AM »
Quote from: patrice58 on June 23, 2010, 04:29:43 AM
In Tim Callan's blog here
https://blogs.verisign.com/ssl-blog/2010/06/incorrect_reports_of_verisign.php
one good point was made which was. Q. Why was Comodo searching for vulnerabilities in VeriSign SSL products?
A. We don't know.
Nor do I so why?
its on our document...we were not....we were searching google!!!!
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #11 on:
June 23, 2010, 06:37:48 AM »
Verisign thinks its ok to have a "Revocation" button publicly available for large banks', so that anyone who can guess the password/passphrase can revoke it from anywhere in the world!!!
Verisign also thinks its ok to publish domains associated with a Bank so that phishers have easy time to figure out which domains they should use next in their phishing attacks.
Verisign also thinks its ok to publish the email addresses of the admin so that social engineering attacks can be mounted!!!
Did Verisign tell its customers that their information is available on Google?
I would like to see Verisign answering these questions, rather then burying their head in the sand and thinking everything is hunky dory!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #12 on:
June 23, 2010, 08:29:32 AM »
Why is Verisign allowing their customer's accounts to be indexed by Google?
What is the benefit?
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12375
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #13 on:
June 23, 2010, 08:34:33 AM »
https://knowledge.verisign.com/support/ssl-certificates-support/index?page=content&id=AD270&actp=LIST&viewlocale=en_US
Now Verisign will have a 6 hour outage to do "maintanence" work on their Certificate Manager.
I thought Verisign said there was no vulnerability
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1706
Re: VeriSign SSL Hackable - Comodo Exposes, VeriSign Denies
«
Reply #14 on:
June 23, 2010, 10:37:52 AM »
Quote
Q. Why was Comodo searching for vulnerabilities in VeriSign SSL products?
A. We don't know.
Propably because they stumbled upon it, Verisign should be gratefull that one of there competitors stumbled it and had it reported
Quote
Verisign will have a 6 hour outage to do "maintenance" work on their Certificate Manager.
If comodo didn't report it, there wouldn't be no 6 hour outage. They should replace the word "maintenance work" to "vulnerably repair" work
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 2.0 Business Edition
===> ESM Console for Windows Phone
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.07 seconds with 18 queries.
Powered by SMF 1.1.16
|
SMF © 2006, Simple Machines
Design by
7dana.com