Internet30.08.2011

Fraudulent Google credentials found online

Google+ logo

DigiNotar, a certificate authority based in the Netherlands, issued the credentials on July 10. The fraudulent credentials were issued to digitally sign Google pages protected by the secure socket layer (SSL) protocol.

The forged certificate is for *.google.com, and allows those in possession of it to execute attacks on a range of Google users who access pages on networks that are controlled by the counterfeit certificates.

“This isn’t a huge surprise,” according to Moxie Marlinspike, a researcher and critic of the SSL system. “This is the kind of thing we should expect is happening all the time. The only thing noteworthy is that anyone noticed.”

Google and Mozilla have responded to the fraudulent credentials by preparing updates to Chrome, Firefox and other software, as well as blocking all sites digitally signed by DigiNotar while the issue is being investigated.

Read the full story over at: The Register.

Show comments

Latest news

More news

Trending news

Poll

Which courier service do you prefer?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter