Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Many thanks to the Tor folks for this disclosure, at least they (and other browser providers) are taking responsibility where Diginotar would not.

It seems likely that Diginotar will be going out of business shortly, and rightly so, but I don't think this should stop there. Their lack of communication is very troubling. Not sure what their contractual obligations are, but when supplying trusted SSL certs trust seems pretty important, so maybe it's possible to sue for damages since that trust was obviously broken?



From the DigiNotar press release [1] on the matter:

    VASCO expects the impact of the breach of DigiNotar’s SSL and EVSSL business
    to be minimal. Through the first six months of 2011, revenue from the SSL 
    and EVSSL business was less than Euro 100,000. VASCO does not expect that
    the DigiNotar security incident will have a significant impact on the
    company’s future revenue or business plans.
[1] - http://www.vasco.com/company/press_room/news_archive/2011/ne...


I refrained from making this comment, before, but I guess I will now.

We should, as well, be running the hell away from VASCO. At a minimum, their due diligence during the acquisition of DigiNotar was lacking. To the extent as the parent company they inherently have responsibility, they have also failed. I don't care if the acquisition is recent; in security, that's no excuse.

Their citation of the monetary figure as reason to consider the matter "minimal" could be read as a further example of their contempt and/or disregard for the responsibility they shouldered with the DigiNotar acquisition.

TL/DR: Stop saying "DigiNotar", and start saying (or also say) "VASCO".


What in the world must DigiNotar's business plan for the future include? How could anyone trust them again? How is it possible that root-level certs were being issued and they've got no warning systems, no logging to determine what actually happened? And remember, we only really know about it now because someone caught the DigiNotar-issued SSL cert floating out in the wild and put it up on Pastebin! As rhizome noted, it borders criminality (if you think about it, does it even border?). These folks told users "Users of SSL certificates can depending on the browser vendor be confronted with a statement that the certificate is not trusted. This is in 99.9% of the cases incorrect, the certificate can be trusted" & their site is full of old defacement tags (on both of these, see http://isc.sans.org/diary/DigiNotar+breach+-+the+story+so+fa... - also worth reading).

The CA system is broked. Everyone's known it for awhile, but man, it's still tough to look straight in the eyes at its brokenness like this.


The whole CA trust model is a complete mess. I suggest interested people to google for the work from moxie marlinspike (@moxie__), e.g., presentation from last BH (http://bit.ly/rbqMCq) and convergence (http://convergence.io/).



As a Dutch citizen, I am ashamed our own government's CA was compromised. And I'm a bit angry, because this hardly concerns just us but the entire secure web.

Frankly, I'm hoping for a lot more than just damages.


No, the Dutch root certificates were not compromised, insofar as I am aware.

Root certs for services provided to the Dutch public were compromised as they were distributed through DigiNotar. The Dutch government has entirely different root certificates and it is where they are currently handing out certificates from to fix various different services that were using the DigiNotar certs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: