HomeinetFake SSL certificates from Symantec are circulating

Fake SSL certificates from Symantec are circulating

Security company Symantec was forced to lay off three employees after Google technicians discovered fake SSL certificates issued in the company's name and used by fraudsters.SSL certificates Symantec

SSL certificates are a technology that allows browsers and Web service providers to establish secure connections and authorized communication channels.

They are used billions of times every day and have become a common practice for securing communications between users and banks, online stores, social networks, as well as for any website that wants to protect its users and their private data from hackers and uninvited government agencies.

Certificate Authorities (CAs) are responsible for issuing these certificates. There are many CAs around the world, and all are recognized by trusted vendors. They issue their certificates only to trusted clients.

One of these CAs is Symantec, a cybersecurity company known primarily for its Norton antivirus.

This Friday, September 18, Google engineers working on Certificate Transparency, a service that checks for fake SSL certificates circulating on the internet, discovered several fake Google.com SSL certificates that had been issued by Symantec. These dangerous certificates were also observed by DigiCert engineers.

What's worse is that these certificates were issued with an "Extended Validation" label, which means that Symantec had supposedly performed additional checks. This information has not been officially confirmed by Google or Symantec in their press releases.

Google has already blacklisted the certificates in question. Since the information was leaked, Google and Symantec do not believe they could be used in real attacks.

If hackers had more time, using these fake SSL certificates they could have carried out MITM (man-in-the-middle) attacks to intercept secure communications.

This was the case in 2011, when Dutch CA company DigiNotar was compromised and hackers managed to issue hundreds of fake SSL certificates. Some of these SSL certificates (also issued in the name of Google) were used by the Iranian government to spy on political dissidents.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS