Google users in Iran targeted in certificate scam

DigiNotar, which issues the Internet security credentials known as SSL certificates, said it had suffered an "intrusion" into its Certificate Authority infrastructure on July 19 which resulted in the fraudulent issuance of public key certificate requests for a number of domains, including Google.com

PTI | September 1, 2011



A false Internet security certificate has been used in an apparent attempt to snoop on Google users in Iran, according to the Internet search giant and computer security firms. A Dutch company, DigiNotar, which issues the Internet security credentials known as SSL certificates, said today that it had revoked the "fraudulent certificate" in question.

SSL certificates are used to verify to visitors that a particular website is authentic and are issued by DigiNotar and other firms known as Certification Authorities. Internet users whose browsers are fooled by a false certificate could unwittingly reveal their activity to another party in what is known as a "man-in-the-middle attack." 

DigiNotar said it had suffered an "intrusion" into its Certificate Authority infrastructure on July 19 which resulted in the "fraudulent issuance of public key certificate requests for a number of domains, including Google.com."

"At that time, an external security audit concluded that all fraudulently issued certificates were revoked," DigiNotar said. "Recently, it was discovered that at least one fraudulent certificate had not been revoked at the time.

"After being notified by Dutch government organization Govcert, DigiNotar took immediate action and revoked the fraudulent certificate," it said.
Google said in a blog post late yesterday that it had "received reports of attempted SSL man-in-the-middle attacks against Google users, whereby someone tried to get between them and encrypted Google services.

"The people affected were primarily located in Iran," said Heather Adkins, an information security manager at Google The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google," she said. Adkins said users of the Google Chrome Web browser were protected from the attack "because Chrome was able to detect the fraudulent certificate."

"To help deter unwanted surveillance, we recommend that users, especially those in Iran, keep their Web browsers and operating systems up to date and pay attention to Web browser security warnings," she added.

Comments

 

Other News

Income Tax dept holds Ghatkopar Outreach on new IT Act

The Income Tax Department organised an outreach programme in Ghatkopar, Mumbai, to raise awareness about the key features of the Income Tax Act, 2025, effective April 1, 2026. The initiative is part of a nationwide effort to promote taxpayer awareness, simplify compliance, and strengthen a transparent, eff

Making AI work where governance is closest to people

India’s next governance leap may not solely come from digitisation. It will come from making public systems more intelligent, more adaptive, and more responsive to the dynamics at the grassroots. That opportunity is especially significant at the panchayat level, where governance is not an abstract po

Borrowing troubles: How small loans are quietly trapping youth

A silent crisis is playing out in the pocket of young India, not in stock markets or government treasuries, but in smartphones of college students and first-jobbers who clicked on the Apply Now button without reading the small print.  A decade ago, to take a loan, you had to do some paperwor

A 19th-century pilgrim’s progress

The Travels of a Sadhu in the Himalayas By Jaladhar Sen (Translated by Somdatta Mandal) Speaking Tiger Books, 259 pages, ₹499.00  

India faces critical shortage of skin donors amid rising burn cases

India reports nearly 70 lakh burn injury cases every year, resulting in approximately 1.4 lakh deaths annually. Experts estimate that up to 50% of these lives could be saved with adequate access to skin donations.   A significant concern is that around 70% of burn victims fall wi

Not just politics, let`s discuss policies too

Why public policy matters Most days, India`s loudest debates stop at the ballot box. We can name every major leader and recall every campaign slogan. Still, far fewer of us can explain why a widow`s pension is delayed or how a government school`s budget is actually approved. That


Archives

Current Issue

Opinion

Facebook Twitter Google Plus Linkedin Subscribe Newsletter

Twitter