Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 18, 2013, 04:19:02 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662831
Posts
70563
Topics
145134
Members
Latest Member:
yura_a
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Business / Enterprise Security Products & Services
Digital Certificates
SSL Certificate
Comodo under attack.
« previous
next »
Pages:
1
2
[
3
]
4
5
...
16
Author
Topic: Comodo under attack. (Read 93590 times)
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4052
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #30 on:
March 25, 2011, 07:49:10 PM »
Quote from: Tech on March 25, 2011, 12:38:07 PM
Microsoft released IE9 with different default settings. Microsoft released a Windows Update for it.
Google released a new version of the browser.
Mozilla seems to be delayed the release of version 4, but did not change the settings (open for this attacks).
None of them said nothing to the users! That is what p*ss me up!
Incorrect, I'm afraid. There were updates to firefox 3.5, 3.6 and version 4 received an impromptu RC2 before final release.
You can read the whole bug here
https://bugzilla.mozilla.org/show_bug.cgi?id=643056#c22
Quote
No, I'm not talking about that.
Then what are you talking about?
Quote
Any proposal depends in a lot of money... and the users are left behind.
Not just money. Are 'users' ever consulted when a major change takes place to the infrastructure of the Internet?
Quote
Seems that Mozilla already recognized that they took the wrong decision and should have warned the users about the problem much before.
You mean in the same way Google did on the 17th March, when they updated their browser. If you read the link I posted above, all three browser owners decided to hold of announcing anything until everyone was ready. In fact, the decision was primarily orchestrated by Microsoft.
Mozilla announced the issue on the 22nd
http://blog.mozilla.com/security/2011/03/22/firefox-blocking-fraudulent-certificates/
when they had patched their browsers. Microsoft made their updates on the 23rd.
http://www.microsoft.com/technet/security/advisory/2524375.mspx
Subsequently, Mozilla have issued a follow-up
http://blog.mozilla.com/security/2011/03/25/comodo-certificate-issue-follow-up/
and also regret delaying the notification to users
Mozilla regrets keeping quiet on SSL certificate theft
I don't see much in the way of apologies from Google or Microsoft. I see even less from Apple and Opera, apart from:
http://my.opera.com/community/forums/topic.dml?id=942542
http://www.h-online.com/security/news/item/Tip-Activating-certificate-checks-in-Safari-1215476.html
Unfortunately, OCSP and CRL have both been seen as problematic and prone to failure.
Why revocation does not work
Quote
Average Joe does not know what to do...
As already stated, there is little the 'average' user can do.
Quote
Certificate Patrol.
Hmmm... Not sure if it is really working.
It works fine.
You can also try
Perspectives
«
Last Edit: March 25, 2011, 08:13:55 PM by Radaghast
»
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #31 on:
March 25, 2011, 08:20:24 PM »
Radaghast, seems I was wrong and read incorrectly the Firefox upgrades. Sorry.
Quote from: Radaghast on March 25, 2011, 07:49:10 PM
I don't see much in the way of apologies from Google or Microsoft. I see even less from Apple and Opera
Oh no, I'm not bashing Mozilla only... I think the users must know what was happening. The others didn't do better than Mozilla I'll say. I have lived situations where the security vendor automatically recognizes the error/problem. I believe in transparency. I trust in people who do that.
By the way, my browser is Firefox 4...
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4052
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #32 on:
March 25, 2011, 08:34:54 PM »
Quote from: Tech on March 25, 2011, 08:20:24 PM
Radaghast, seems I was wrong and read incorrectly the Firefox upgrades. Sorry.
Oh no, I'm not bashing Mozilla only... I think the users must know what was happening. The others didn't do better than Mozilla I'll say. I have lived situations where the security vendor automatically recognizes the error/problem. I believe in transparency. I trust in people who do that.
By the way, my browser is Firefox 4...
No worries. I too believe all concerned should have done a much better job informing their users and issuing their respective patches earlier. Unfortunately, there's more going on here than we're being told. No doubt the full story will emerge, eventually...
Firefox 4 is doing quite well, there are problems, but they'll be addressed as we go forward. I use the nightly build, so I'm currently using 4.2a1pre, which will eventually make way for version 5. (although there may be an couple of interim releases...)
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #33 on:
March 26, 2011, 10:42:00 AM »
A very good and serene reading about what happened, the Comodo and Mozilla actions.
http://blog.mozilla.com/security/2011/03/25/comodo-certificate-issue-follow-up/
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4052
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #34 on:
March 26, 2011, 07:42:41 PM »
Quote from: Tech on March 26, 2011, 10:42:00 AM
A very good and serene reading about what happened, the Comodo and Mozilla actions.
http://blog.mozilla.com/security/2011/03/25/comodo-certificate-issue-follow-up/
I've already given that link in the post above...
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #35 on:
March 26, 2011, 08:25:53 PM »
Quote from: Radaghast on March 26, 2011, 07:42:41 PM
I've already given that link in the post above...
Sorry. Too many posts and links about the same.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
ichsun
Newbie
Offline
Posts: 1
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #36 on:
March 27, 2011, 09:39:37 AM »
Have you ever seen Hacker's response:
http://pastebin.com/74KXCaEZ
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4052
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #37 on:
March 27, 2011, 10:00:39 AM »
Sounds like a self-congratulatory political diatribe from an attention seeking wannabe.
Quote
... I should mention my age is 21
And this matters, why?
Follow-up post
http://pastebin.com/DBDqm6Km
Quote
public ASCR ()
{
this.url = "
https://secure.comodo.net/products/
";
this.url_nos = "
https://secure.comodo.net/products/
";
this.login = "gtadmin";
this.password = "TRIMMEDIT";
this.numberOfTries = 5;
}
If that's true, it's pretty poor...
«
Last Edit: March 27, 2011, 09:54:06 PM by Radaghast
»
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #38 on:
March 28, 2011, 05:17:20 AM »
Quote
I heard that some stupids tried to ask about it from Iran's ambassador in UN, really? How smartass you are?
Where were you when
Stuxnet created by Israel and USA with millions of dollar budget, with access to SCADA systems and Nuclear softwares?
Why no one asked a question from Israel and USA ambassador to UN?
So you can't ask about SSL situtation from my ambassador, I answer your question about situtation: "Ask about Stuxnet from USA and Israel", this is your answer, so don't waste my Iran's ambassador's worthy time.
When
USA and Isrel can read my emails in Yahoo, Hotmail, Skype, Gmail, etc. without any simple
little problem,
when they can spy using
Echelon
, I can do anything I can. It's a simple rule. You do,
I do, that's all. You stop, I don't stop. It's a rule, rule #1 (My Rules as I rule to internet, you should know it
already...)
Rule#2: So why all the world worried, internet shocked and all writers write about it, but nobody
writes about Stuxnet anymore? Nobody writes about
HAARP
, nobody writes about Echelon... So nobody
should write about SSL certificates.
Rule#3: Anyone inside Iran with problems, from
fake green movement
to all MKO members and two faced
terrorists, should afraid of me personally. I won't let anyone inside Iran, harm people of Iran, harm
my country's Nuclear Scientists, harm my Leader (which nobody can), harm my President, as I live, you
won't be able to do so. as I live, you don't have privacy in internet, you don't have security in
digital world, just wait and see...By the way, you already have seen it or you are blind,
is there any larger target than a CA in internet?
Seems like I am not a crazy conspiracy nut after all...
I would like some explanation, please....
Logged
kail
Mostly Benevolent
Global Moderator
Comodo's Hero
Offline
Posts: 10753
The future is much like the present, only longer.
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #39 on:
March 28, 2011, 05:39:45 AM »
Quote from: GakunGak on March 28, 2011, 05:17:20 AM
Seems like I am not a crazy conspiracy nut after all...
That remains to be seen.
Quote from: GakunGak on March 28, 2011, 05:17:20 AM
I would like some explanation, please....
I assume the
bold
highlighting is yours. But, it's not exactly clear (to me at least) what you would like an explanation on or from whom.
Logged
System Details: W7x64U with CIS 6, Firefox 20, IceDragon 20 & Becky! 2.65
Forum Policy
.
____
I don't know what weapons countries might use to fight World War III, but wars after that will be fought with sticks and stones. Einstein
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #40 on:
March 28, 2011, 05:44:12 AM »
Sorry, my apologies, I did not format it good enough, my bad!
I would like to know what is Comodo's stance of user privacy, what data is collected and what is being done to ensure user privacy and security on the internet.
What is Comodo's stance on Stuxnet?
Can Comodo protect it's users from intelligence gathering from three-letter-agencies? [I do not say to cover criminals, but to respect privacy of ordinary users!]
It indeed is bold on my part....
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4052
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #41 on:
March 28, 2011, 06:01:29 AM »
Quote from: GakunGak on March 28, 2011, 05:44:12 AM
Sorry, my apologies, I did not format it good enough, my bad!
I would like to know what is Comodo's stance of user privacy, what data is collected and what is being done to ensure user privacy and security on the internet.
What is Comodo's stance on Stuxnet?
Can Comodo protect it's users from intelligence gathering from three-letter-agencies? [I do not say to cover criminals, but to respect privacy of ordinary users!]
It indeed is bold on my part....
And this has do to with the 'hacked' certificates, what exactly?
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #42 on:
March 28, 2011, 06:10:48 AM »
The hacker claims to protect himself, his people and his government from cyber attacks, fake protests etc....
Why did he specifically target Comodo when he could do Verizon or other company?
Logged
kail
Mostly Benevolent
Global Moderator
Comodo's Hero
Offline
Posts: 10753
The future is much like the present, only longer.
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #43 on:
March 28, 2011, 06:17:57 AM »
Quote from: GakunGak on March 28, 2011, 06:10:48 AM
Why did he specifically target Comodo when he could do Verizon or other company?
I'm guessing that it's because Verizon isn't a
CA
.
Logged
System Details: W7x64U with CIS 6, Firefox 20, IceDragon 20 & Becky! 2.65
Forum Policy
.
____
I don't know what weapons countries might use to fight World War III, but wars after that will be fought with sticks and stones. Einstein
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
«
Reply #44 on:
March 28, 2011, 06:19:46 AM »
Sorry, Verisign!
From link:
http://en.wikipedia.org/wiki/Certificate_authority#Providers
. A 2009 market share report from Net Craft as of January of that year determined that
VeriSign
and its acquisitions (which include Thawte and Geotrust) have a
47.5%
share of the certificate authority market, followed by GoDaddy (23.4%), and Comodo (15.44%).
Logged
Tags:
Pages:
1
2
[
3
]
4
5
...
16
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.057 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com