Asyn
March 23, 2011, 9:35pm
1
Asyn
March 23, 2011, 10:05pm
3
@doc : You thread @comodo has been restored. (Thanks Bob…!!!)
https://forums.comodo.com/ssl-certificate/comodo-issues-fraudulent-google-microsoft-mozilla-skype-yahoo-certificates-t70990.0.html;msg504253#msg504253
All
My mistake, I’d forgotten that the Forum Policy Violation Board is no longer visible and what I had done was not transparent.
The original topic has been restored, less the offending posts.
Comodo issues fraudulent Google, Microsoft, Mozilla, Skype, Yahoo certificates
Sal: Thanks, I should had thought of that sooner. Smiley
system
March 23, 2011, 10:56pm
4
this is all new to me, thanks guys ;D
system
March 23, 2011, 10:58pm
5
Haha… not my account though.
@mods : Would be nice to split the stuff from the original thread and move it here.
system
March 23, 2011, 11:03pm
6
Asyn
March 23, 2011, 11:09pm
7
system
March 23, 2011, 11:12pm
8
See below. (No, I don’t need the account back, haven’t been there for like 2 years).
Asyn
March 23, 2011, 11:12pm
9
system
March 23, 2011, 11:17pm
10
@Asyn okay
Hmm guys… I see a major problem here, the “other” doctornotor is saying that FF4 RC2 was justified to block fraulent certificates. Fair enough… but FF has its own certificate store while Chrome is using Windows/IE store… and as far as I’m concerned unless MS sends an update through Windows Update IE8/9 and Chrome are vulnerable. Got to say that the ZDnet article is …hmm… worrying
http://www.zdnet.com/blog/security/microsoft-warns-fraudulent-digital-certificates-issued-for-high-value-websites/8488?tag=nl.e589
ps: lol, funny I updated to RC2 a few days ago and the only thing I found was that Mozilla corrected a last minute bug… but the article didn’t say what… I didn’t really care and should have searched other places…
system
March 23, 2011, 11:22pm
11
Hmm guys… I see a major problem here, the “other” doctornotor is saying that FF4 RC2 was justified to block fraulent certificates. Fair enough… but FF has its own certificate store while Chrome is using Windows/IE store… and as far as I’m concerned unless MS sends an update through Windows Update IE8/9 and Chrome are vulnerable. Got to say that the ZDnet article is …hmm… worrying
Already out as critical update on WU and WSUS. Also manual d/l via http://support.microsoft.com/kb/2524375 (from XP up to Server 2008 R2)
P.S. IE and Chrome is doing it the right way ™ - bundling its own certificates crap is plain wrong, and nightmare to manage in business environment.
system
March 23, 2011, 11:25pm
12
yeah I just saw that in the article:
Microsoft has pushed out an update for all supported versions of Windows to help address this issue and notes that no action is required from Windows users with automatic update enabled. The company’s advisory contains instructions on manually applying the update.
edit: KB2524375 (W7/64) already available directly from Windows update.
system
March 23, 2011, 11:41pm
13
Apparently the morons @ Comodo have not heard about DNSSEC yet either ; ugh. :
Melih the victim of Iranian govt.:
If there was a secure and trusted DNS this issue would be a moot point! We need a Secure and Trusted DNS!
Now we are living in a new era where people who provide Authentication to end users are target for State-funded entities! Its a new era indeed…brace yourselves…
Melih
:-X :
system
March 23, 2011, 11:54pm
14
lol… the guy feels guilty ;D now he’s trying to put the weight on DNS servers shoulders : same old Melih…
Asyn
March 23, 2011, 11:54pm
15
Seems, they’re searchin for flimsy excuses.
system
March 23, 2011, 11:58pm
16
lol on a side note, I don’t think anything worse could happen to Comodo. Officially they got screwed themselves (stolen credentials of an Comodo ssl cert provider)… now we don’t know and we might never know how it happened…
For the ones who do not know what could happen:
These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.
Asyn
March 24, 2011, 12:14am
19
Thanks, Tech.
Everyone, who answered here is aware of the risks.
Still, if other users should follow this thread, it won’t hurt to offer some basic feedback.
Hi guys, as I don’t want this thread to become a discussion thread.
Please post further replies to the Comodo issue here: http://forum.avast.com/index.php?topic=74516.0
Thanks,
asyn
Edit: Or follow Tech’s link to WSF… (Thanks Tech…!!)
It would be a lot nicer to do it directly on the Comodo forum . :0