Author Topic: Technical  (Read 1487369 times)

0 Members and 1 Guest are viewing this topic.

doktornotor

  • Guest
Re: Technical
« Reply #75 on: March 23, 2011, 01:20:27 PM »
Quote
This issue was reported to us by the Comodo Group, Inc., the certificate authority responsible for issuing the fraudulent certificates.

Oh, what a surprise. We've been discussing this a couple of days ago wrt CIS vendor whitelists, haven't we?  :D

Comodo vs Mozilla 2008 story (also here).

Oh, and on a preventive note: How to disable the Comodo reseller root certificate in Firefox. (For IE and Chrome, certmgr.msc MMC snap-in is your friend.  ;))
« Last Edit: March 23, 2011, 01:32:25 PM by doktornotor »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #76 on: March 23, 2011, 01:31:41 PM »
Quote
This issue was reported to us by the Comodo Group, Inc., the certificate authority responsible for issuing the fraudulent certificates.

Oh, what a surprise. We've been discussing this a couple of days ago wrt CIS vendor whitelists, haven't we?  :D

Yes, you a right, doc..!! It's really a big surprise. ;D
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48541
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Technical
« Reply #77 on: March 23, 2011, 01:56:48 PM »
Isn't "Trust" what Comodo sells ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #78 on: March 23, 2011, 02:00:09 PM »
Isn't "Trust" what Comodo sells ???

Bad job then. ;D
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

doktornotor

  • Guest
Re: Technical
« Reply #79 on: March 23, 2011, 03:38:17 PM »
Isn't "Trust" what Comodo sells ???

Let's have some phun: Comodo issues fraudulent certificates (incl. Mozilla) once again @ Comodo forums. Wondering how long will the thread last.  :P ;D

EDIT: Thread moved to Policy Violations forum after banning me (Requires registation @ Melih's hunted by Iran government forums ;D)
« Last Edit: March 23, 2011, 09:06:28 PM by doktornotor »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #80 on: March 23, 2011, 03:44:47 PM »
Wondering how long will the thread last.  :P ;D

I wonder, too. ;)
You may add this, if you like...

SSL meltdown forces browser developers to update
http://www.h-online.com/security/news/item/SSL-meltdown-forces-browser-developers-to-update-1213358.html
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

doktornotor

  • Guest
Re: Technical
« Reply #81 on: March 23, 2011, 03:51:41 PM »
SSL meltdown forces browser developers to update
http://www.h-online.com/security/news/item/SSL-meltdown-forces-browser-developers-to-update-1213358.html

Thanks. Couldn't agree more with this:

Quote
The incident is further proof that the entire concept of SSL and of users' trust in the Certificate Authorities are standing on feet of clay. After all, a certificate is also considered trustworthy even if it is issued by a CA reseller based in a country to which users probably wouldn't even go on holiday for security reasons. And the promised technologies don't even work when a compromised certificate is made public. It is time to come up with a new concept – and "EV-SSL" certificates, at least, should not be a part of it.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #82 on: March 23, 2011, 03:55:22 PM »
NP, doc..!!
Now, let's sit and wait for the replies. ;D 8)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

doktornotor

  • Guest
Re: Technical
« Reply #83 on: March 23, 2011, 06:30:55 PM »
NP, doc..!!
Now, let's sit and wait for the replies. ;D 8)

Looks like the Comodo morons also issued a fraudulent certificate for login.live.com (Windows Live ID), not just addons.mozilla.org  ::)

Microsoft Releases Security Advisory 2524375

Quote
Today we're releasing Security Advisory 2524375, to address nine fraudulent digital certificates issued by Comodo Group Inc, a root certificate authority. Comodo has since revoked the digital certificates. This is not a Microsoft security vulnerability; however, one of the certificates potentially affects Windows Live ID users via login.live.com. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against end users. We are unaware of any active attacks.

Wow, and login.skype.com, login.yahoo.com and www.google.com and mail.google.com - just excellent.

Already got KB2524375 via Windows Update.
« Last Edit: March 23, 2011, 06:45:29 PM by doktornotor »

doktornotor

  • Guest
Re: Technical
« Reply #84 on: March 23, 2011, 08:15:10 PM »
Ok, guys, now it's official, no sloppy job or anything, instead - Iran has attacked Melih and Comodo!!!!.

Quote
Who is attacking it?
We believe these are “politically motivated”, “state driven/funded” attacks.

Why do we think these are state driven/funded?
Well, one of the origin of the attack that we experienced is from Iran, what is being obtained would enable the perpetrator to intercept web based email/communication and the only way this could be done is if the perpetrator had access to the Country’s DNS infrastructure (and we believe it might be the case here). Of course this is our interpretation of the situation.

First time we are seeing a “state funded” attack against the “Authentication” infrastructure. The Threat Model is changing and Comodo had already initiated a proposal for new standards in 2010 which would help mitigate some of these attacks. We will make sure to double our efforts in getting industry wide acceptance to these much needed standards so that we can continue to defend our security and freedom.

 :o ;D :o ;D :o ;D

P.S. Mozilla Bug 642395 - Deal with bogus certs issued by Comodo partner
« Last Edit: March 23, 2011, 08:18:33 PM by doktornotor »

doktornotor

  • Guest
Re: Technical
« Reply #85 on: March 23, 2011, 09:01:12 PM »
Let's have some phun: Comodo issues fraudulent certificates (incl. Mozilla) once again @ Comodo forums. Wondering how long will the thread last.  :P ;D

Did not last long:

Quote
An Error Has Occurred!
Sorry doktornotor, you are banned from using this forum!
Forum Policy Violation

;D :D ;D :D

P.S. Thread moved here: (requires registration). Well whatever - here's the sequel for you. Bye bye Comodo. Sincerely yours, Comodo's Hero.  :P

« Last Edit: March 23, 2011, 09:03:48 PM by doktornotor »

YoKenny

  • Guest
Re: Technical
« Reply #86 on: March 23, 2011, 09:09:01 PM »
Let's have some phun: Comodo issues fraudulent certificates (incl. Mozilla) once again @ Comodo forums. Wondering how long will the thread last.  :P ;D

Did not last long:

Quote
An Error Has Occurred!
Sorry doktornotor, you are banned from using this forum!
Forum Policy Violation

;D :D ;D :D

P.S. Thread moved here: (requires registration). Well whatever - here's the sequel for you. Bye bye Comodo. Sincerely yours, Comodo's Hero.  :P

Comodo's Melih does not like critics.  ;)


Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48541
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

doktornotor

  • Guest
Re: Technical
« Reply #88 on: March 23, 2011, 09:45:34 PM »
https://forums.comodo.com/ssl-certificate/comodo-issues-fraudulent-google-microsoft-mozilla-skype-yahoo-certificates-t70990.0.html

Haha... Well, as I said on the original thread - their image cannot be harmed much more no matter how much their censored the forums...

Oh, and remember, Iran government is going after them!  :o

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Technical
« Reply #89 on: March 23, 2011, 10:23:36 PM »
I've started the discussion in a neutral field.
http://www.wilderssecurity.com/showthread.php?p=1847026#post1847026
The best things in life are free.