Password creation policies are the enemy of secure... » Commenting on reports that a security developer has concluded that password-creation policies are th... Thousands of Young Adventurers kept safe with M2M ... » Thousands of teenagers taking part in the annual two-day Ten Tors Challenge across Dartmoor in Devon... avast! Free Antivirus for Mac tops CNET’s download... » PRAGUE, Czech Republic: Three days after its release avast! Free Antivirus for Mac shot to first pos... USB-Tischmikrofone von Imtradex gewährleisten schn... » TM2-LS und TM3 verbinden innovative Technik mit einfacher Handhabung Dreieich: Schnelle und einfach... Opengear wins Information Technology Industry’s 20... » Opengear ACM5504-5-G-I Remote Infrastructure Management Gateway Honored at Interop Interop, Las Veg... ISACA Speaker urges IT candidates to shift career ... » In-depth discussion to be held at INSIGHTS 2012 London, UK: Recruiting in the technology sector is ... Venafi hails FBI’s hotel-network security warning ... » London: “Everyone with an Internet connection has a stake in understanding the critical links in the... Is loaphobia causing workers to fear losing their ... » 19% missed a critical deadline because they couldn’t access the right applications, 14% lost a job a... Whoopee! £38 billion blackhole in Defence budget e... » Vigilance can report that the MoD’s budget deficit has been wiped out for the first time in a genera... Media Alert: DDoS tool (LOIC) downloads increasing... » Imperva's Application Defense Centre has been tracking the Anonymous DDoS tool, LOIC, and the number...

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to our Newsletter

Information Security Header

Verisign have revealed that hackers have taken stolen undisclosed information on numerous occasions.

The VeriSign attacks were revealed in a quarterly U.S. Securities and Exchange Commission filing in October that followed new guidelines on reporting security breaches to investors. It was the most striking disclosure to emerge in a review by Reuters of more than 2,000 documents mentioning breach risks since the SEC guidance was published.

 

The article speculates that penetrating SSL certificates may have been a key target of the attack.

Until August 2010, VeriSign was one of the largest providers of Secure Sockets Layer certificates, which Web browsers look for when connecting users to sites that begin "https," including most financial sites and some email and other communications portals.

If the SSL process were corrupted, "you could create a Bank of America certificate or Google certificate that is trusted by every browser in the world," said prominent security consultant Dmitri Alperovich, president of Asymmetric Cyber Operations.

This shouldn't surprise anyone. As we wrote late in 2011, while a growing number of web applications are delivered over the HTTPS protocol (HTTP over SSL), attackers are increasingly focusing their attacks against the various components of SSL. We are seeing a rise in attacks which target the worldwide infrastructure that supports SSL. We expect these attacks to reach a tipping point in 2012 which, in turn, will invoke a serious discussion about real alternatives for secure web communications. The VeriSign attack highlights that the tipping point may have actually arrived in 2011.

Add comment


Security code
Refresh