Author Topic: Comodo - SSL issues  (Read 83764 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Comodo - SSL issues
« Reply #90 on: March 31, 2011, 12:32:37 AM »
Too complex reading... Can anybody say what did really happen or is happening?

Too complex..??? ;)
Well, here's the short version: http://www.h-online.com/security/news/item/Comodo-two-more-resellers-were-compromised-1218517.html
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Comodo - SSL issues
« Reply #91 on: March 31, 2011, 12:37:16 AM »
Now it's better and in plain English :)
The best things in life are free.

sded

  • Guest
Re: Comodo - SSL issues
« Reply #92 on: March 31, 2011, 12:48:08 AM »
http://www.wilderssecurity.com/showthread.php?t=295617 seems to get pretty thorough updating.

doktornotor

  • Guest
Re: Comodo - SSL issues
« Reply #93 on: March 31, 2011, 10:46:13 PM »
Too complex reading... Can anybody say what did really happen or is happening?

Sure thing. Comodo sucks goats nuts... and more.  ;D


Hermite15

  • Guest
Re: Comodo - SSL issues
« Reply #94 on: March 31, 2011, 10:51:47 PM »
lol ;D ;D ;D

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Comodo - SSL issues
« Reply #95 on: April 01, 2011, 03:14:23 PM »
Sorry if it was posted before...
But a serene and very good reading about what happened, what have been done, the responsibility of each part of the process.
http://samuelsidler.com/2011/03/28/timeline-of-comodo-certificate-compromise/
The best things in life are free.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Comodo - SSL issues
« Reply #96 on: April 01, 2011, 03:25:02 PM »
Sorry if it was posted before...

I like the timeline approach.
But it's not complete, newer info has been posted here already...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Comodo - SSL issues
« Reply #97 on: April 02, 2011, 10:05:58 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Was: What could be the possible reason?
« Reply #98 on: April 02, 2011, 05:39:20 PM »
Well I find Outpost in many ways ahead to comodo. And how can comodo help me if a 21 years old boy from Iran hacked into its system and generated 4-5 Security Certificates ??
What is the minimum relationship between the Comodo firewall and the certificates issued?
This is just FUD.
The best things in life are free.

doktornotor

  • Guest
Was: What could be the possible reason?
« Reply #99 on: April 02, 2011, 05:40:57 PM »
What is the minimum relationship between the Comodo firewall and the certificates issued?

Hmmm... the TVL perhaps?

Offline Ashish Singh

  • Poster
  • *
  • Posts: 437
  • Proud to be an Indian
    • Quick Heal
Was: What could be the possible reason?
« Reply #100 on: April 02, 2011, 05:50:36 PM »
As a 21 years old boy can hack into their system with so ease I wonder if they can't defend their own system then how come mine??
They were using "gtadmin" (gt stands for Global Trust) as their username and the password was "globaltrust" isn't it a good joke for a company who is issuing a Security Public key and Private one also and uses such a weak username and password. Then how can I trust their firewall policies???
Windows 7 Ultimate(32 bit), avast! free (always latest released or beta), Intel Core2Duo, 2GB RAM, Outpost Firewall Pro 7.5,IE 9,TuneUp Utilities 2011,Diskeeper 2011

http://www.incredibleindia.org 

Caution! Online world is full of man made Aliens

Offline Ashish Singh

  • Poster
  • *
  • Posts: 437
  • Proud to be an Indian
    • Quick Heal
Was: What could be the possible reason?
« Reply #101 on: April 02, 2011, 05:59:30 PM »
And ya as this is not a comodo forum or Outpost one so better leave this topic here only.
But comodo needs to grow more. Thanks for your support....
Windows 7 Ultimate(32 bit), avast! free (always latest released or beta), Intel Core2Duo, 2GB RAM, Outpost Firewall Pro 7.5,IE 9,TuneUp Utilities 2011,Diskeeper 2011

http://www.incredibleindia.org 

Caution! Online world is full of man made Aliens

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Was: What could be the possible reason?
« Reply #102 on: April 02, 2011, 06:03:15 PM »
Hmmm... the TVL perhaps?
No, absolutely nothing.

As a 21 years old boy can hack into their system
Which system? The boy entered the certification and SSL system which does not belong only to Comodo.
Did you read the technical information about the subject?

I wonder if they can't defend their own system then how come mine??
It's not their system. It's your system. It's our Internet.

They were using "gtadmin" (gt stands for Global Trust) as their username and the password was "globaltrust" isn't it a good joke for a company who is issuing a Security Public key and Private one also and uses such a weak username and password.
A serious link reporting this issue, please.

Then how can I trust their firewall policies???
Which software will you trust then?
avast?
Are you sure avast didn't make any mistake in the past?
C'mon... Hint: statistics of the forum and date 3-12-09 will show you one trouble problem in our history...
The best things in life are free.

doktornotor

  • Guest
Was: What could be the possible reason?
« Reply #103 on: April 02, 2011, 06:26:00 PM »
Hmmm... the TVL perhaps?
No, absolutely nothing.

Really? Doing absolutely sloppy job with highly sensitive things such as RAs, how much work do you think goes into verification of so called "trusted" vendors hardcoded into CIS? Well, I can tell you - absolutely none. Pay for the certs and sign whatever you want, you will get on TVL as a bonus so that your malware installs cleanly without hassle for users. Quite a couple of threads about this on Comodo forums, incl. a trojan signed by fake Trend Micro cert.  ::) >:(

Hermite15

  • Guest
Was: What could be the possible reason?
« Reply #104 on: April 02, 2011, 06:43:32 PM »
Hmmm... the TVL perhaps?
No, absolutely nothing.

Really? Doing absolutely sloppy job with highly sensitive things such as RAs, how much work do you think goes into verification of so called "trusted" vendors hardcoded into CIS? Well, I can tell you - absolutely none. Pay for the certs and sign whatever you want, you will get on TVL as a bonus so that your malware installs cleanly without hassle for users. Quite a couple of threads about this on Comodo forums, incl. a trojan signed by fake Trend Micro cert.  ::) >:(

+1 I already didn't trust Comodo anymore before that...this ssl disaster fits Comodo so well... ie I don't trust their "official" versions of what happened at all. I now would consider any of their product potentially malicious.