iPhone app iPad app Android phone app Android tablet app More

Iran Involvement Suspected In DigiNotar Security Firm Hacking: Experts

Iran Diginotar Hack

By TOBY STERLING   09/ 5/11 01:25 PM ET   AP

AMSTERDAM -- Hackers who broke into a Dutch web security firm have issued hundreds of bogus security certificates for spy agency websites including the CIA as well as for Internet giants like Google, Microsoft and Twitter, the government said Monday.

Experts say they suspect the hacker – or hackers – operated with the cooperation of the Iranian government.

So far, only a handful of users in Iran are known to have been affected. In addition, the latest versions of browsers such as Microsoft's Internet Explorer, Google's Chrome and Mozilla's Firefox are now rejecting certificates issued by the firm that was hacked, DigiNotar.

But in a statement Monday, the Dutch Justice Ministry published a list of the fraudulent certificates that greatly expands the scope of the July hacking attack that DigiNotar first acknowledged last week. The list includes sites operated by Yahoo, Facebook, Microsoft, Google, Skype, AOL, Mozilla, TorProject, and WordPress, as well as spy agencies including the CIA, Israel's Mossad and Britain's MI6.

DigiNotar is one of many companies which sell the security certificates widely used to authenticate websites and guarantee that communications between a user's browser and a website are secure.

In theory, a fraudulent certificate can be used to trick a user into visiting a fake version of a website, or used to monitor communications with the real sites without users noticing.

But in order to pass off a fake certificate, a hacker must be able to steer his target's Internet traffic through a server he controls. That's something that only an Internet service provider can easily do – or a government that commands one.

Technology experts cite a number of reasons to believe the hacker – or hackers – were based in Iran and cooperated with the Iranian government, perhaps in attempts to spy on dissidents. Notably, several of the certificates contain nationalist slogans in the Farsi language.

"This, in combination with messages the hacker left behind on DigiNotar's website, definitely suggests that Iran was involved," said Ot van Daalen, director of Bits of Freedom, an online civil liberties group.

The hack of DigiNotar closely resembles one in March of the U.S. security firm Comodo Inc., which was also attributed to an Iranian hacker.

Gervase Markham, a Mozilla developer who has been involved in the response to the DigiNotar failure, warned Iranian Internet users on Monday to update their browsers, "log out of and back into every email and social media service you have" and change all passwords.

Van Daalen said he believed the DigiNotar incident will ultimately lead to a reform of authentication technology.

Although no users in the Netherlands are known to have been victimized directly by the hack, it has caused a major headache for the Dutch government, which relied on DigiNotar for authentication of most of its websites.

In a pre-dawn press conference Saturday, Justice Minister Piet Hein Donner said the safety of websites including the country's social security agency, police and tax authorities could no longer be guaranteed.

He advised users who wanted to be certain of secure communication with the government to return to using pen and paper.

The Dutch government took over management of DigiNotar, a subsidiary of Chicago-based Vasco Inc., but kept the websites operating as it scrambles to find replacement security providers.

FOLLOW HUFFPOST TECH

AMSTERDAM -- Hackers who broke into a Dutch web security firm have issued hundreds of bogus security certificates for spy agency websites including the CIA as well as for Internet giants like Google, ...
AMSTERDAM -- Hackers who broke into a Dutch web security firm have issued hundreds of bogus security certificates for spy agency websites including the CIA as well as for Internet giants like Google, ...
Filed by Catharine Smith  | 
 
 
  • Comments
  • 114
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
Page: 1 2 3 4  Next ›  Last »  (4 total)
photo
karim banned
A fool's mind is at the mercy of his tongue and a
12:36 PM on 09/13/2011
Sounds like a retaliation for suntracs virus!

Iran is less vulnerable to virus attacks since it does not rely so much as West does on the computers. I think nobody in West had predicted a retaliation for suntracs virus.

Only the Zionist warmongers and Israel will benefit from attacking another Muslim country. With Syria in sight, Iran or Lebanon will be next target.

West should free itself from the control of the warmongers. Zionist will suck the last drop of the increasingly weakened society in the West until there is no life left. Then they will move to the next victum.

Unfortunately it is hard to penetrate China, the next healthy nation,and Westerners will suffer for long time to come. They just pulled stunt like 9/11 and they got away with it. This emboldened them to think they can get away with anything. Soon or later physical needs of the people will sharpen their senses and they will discover they lies they have been told one after other. Internet is the key for free information and companies like Google are there to control the flow of information. It is funny how predator plays the role of victim to get sympathy agaist Big Bad Wolf, Iran.

Say no to new slavery and free yourself from Zionists who control every aspect of life in West.
photo
HUFFPOST SUPER USER
Charles Queen
I am a disabled nam vet
02:18 AM on 09/10/2011
I'v always' beleieved that Iran has been behind a lot of the hacking thats been done ans is being doen in attempts tp breach our national securirty programs.pentagon,cia etc.I also definitle believe that china has been guilty of doing this exact same thing no matter how much they cry that they had nothing to do with any of it
photo
HUFFPOST SUPER USER
walkingwolf
I'm sorry I offended you-I should have lied
04:47 AM on 09/07/2011
And if you like IRAN Stop sending me replys'' because I'm not gonna respond with anything but contempt.
photo
HUFFPOST SUPER USER
walkingwolf
I'm sorry I offended you-I should have lied
04:46 AM on 09/07/2011
to all of you pro Iranian lovers..hey if you don't like my America even with its problems..and you think Iran is so much better THEN GET THE F*** OUT OF MY COUNTRY.
11:38 AM on 09/07/2011
It isn't YOUR country.  I'm American red, white and blue.  But I also support the Iranian people.  Get over yourself.
photo
HUFFPOST SUPER USER
Charles Queen
I am a disabled nam vet
02:22 AM on 09/10/2011
I support the I ranian people because they hate their current leaders and for good reason.They have to live day in and day out wondering if their going to be the next ones arrested on trumped up charges for simply saying something bad about their fearless leader or some other stupid cgarge having to do with thenm not likng their leader(s).The only reason that they havn't tryed to revolt or protest is because they cannot get the weapons they need in order to do so.Their govermnet has made certain that the people are not going to get their hands on the weapons they need to revolt
photo
HUFFPOST SUPER USER
wsa999
11:50 PM on 09/06/2011
Apparently some of these people do have jobs over there and they're not protesting all over the streets.
photo
hackitoff
question everything
11:05 PM on 09/06/2011
Could it really have been the CIA, MI6, MOSSAD, NSA or even NASA (nothing to do since the shuttle program was cancelled). :)
photo
hackitoff
question everything
11:03 PM on 09/06/2011
Could it have been Chinese hackers masquerading as Iranian hackers?
07:23 PM on 09/07/2011
No way this is one of the biggest hacks against the Iranian people. This hack went on for over a month before DIGINotar found out. Such bad security on a site that has so much power. It was a local Student with permission from the Iranian government. We are tracking them now as we speak.

http://USCyberLabs.com/blog/
http://cyber.uscyberlabs.com
http://ChinaCyberWarfare.wordpress.com
http://HacktivistBlog.wordpress.com/
10:08 PM on 09/06/2011
Smells some fresh baked war propaganda
photo
majorg1000
One Nation, Underfed
10:10 PM on 09/06/2011
Zactly!
10:20 PM on 09/06/2011
something for romney, santorum, and perry to use as an excuse to justify war with iran in the next debates as well
09:48 PM on 09/06/2011
Oppressing their own people? So what. Supporting terrorism? So what. Hacking Google? Nuke 'em!
photo
HUFFPOST SUPER USER
rightfromwrong
it's not the years in your life that count, its th
09:48 PM on 09/06/2011
sure!! blame iran. dont explain why. just blame them!
photo
HUFFPOST SUPER USER
Seawolf56
Truth should never be censored
09:31 PM on 09/06/2011
OMG I guess Iran is so bad that we need to let Israel bomb it!! Planted story!! Paid for by???
09:08 PM on 09/06/2011
IRAN, or a suspect that lives in IRAN, Dont get it twisted or fall into this media Hype. First is was Iraq on the WMD'S (oil) Then Lybia (oil) Next is IRAN.
08:49 PM on 09/06/2011
Airborne sterilization of the country is doable , bloodless and appropriate... 20 years no more enemy. It also ruduces mans burden on the planet
photo
HUFFPOST SUPER USER
bobknot131
Jason Vorhees for the win.
07:45 PM on 09/06/2011
iran likes to start a lot of things for no good reasons but i thought the chinese are the ones who go after data no iranians.
07:05 PM on 09/06/2011
hmmm,,,
this could be a part of the setup by Operation Shady Rat (reported by McAfee) , which MSM has trumpeted to be "most likely" done by China, and which was also raised doubts from other security firms -- http://www.computerworld.com/s/article/9218910/_Shady_RAT_hacking_claims_overblown_say_security_firms