Incidents

A Web of (Mis)Trust?

At our international press tour held in Moscow in early February, we spoke about the dissolution of trust on the internet and discussed
the possibility of Certificate Authority subversion and the impact of abused digital certificates.

Our speculation was partly driven by the abuse of trust that Kaspersky Lab monitored and prevented by the stolen Stuxnet digital certificates.

This unfortunate moment is arriving sooner than we wanted. This past week, another concrete example of the very foundation of trust on the web was shaken with the final coordination of an effort between a compromised Certificate Authority and web browser providers. The compromised Certificate Authority and browser developers needed to denylist a set of digital certificates for high value sites that malicious attackers issued for their own use. The end result is that attackers assumed the credibility of some major web presences with the assurance of the Certificate Authority. Mozilla provided brief description of impact: “Users on a compromised network could be directed to sites using the fraudulent certificates and mistake them for the legitimate sites. This could deceive them into revealing personal information such as usernames and passwords. It may also deceive users into downloading malware if they believe it’s coming from a trusted site.”

What does that mean to you? Well, a short list of some of the impacted sites include:
login.live.com
mail.google.com
www.google.com
login.yahoo.com (3 certificates)
login.skype.com
addons.mozilla.org
“Global Trustee”

In a hypothetical scenario, you may have received an email with a link that you clicked on, or your browser may have been redirected to what appeared to be one of these sites. The browser indicated that it trusts the site, so you login with your user and pass. For some reason, you get redirected and login again to the site. At this point, a part of your online identity and access to your email or IM is compromised by an attacker. Again, this is purely hypothetical.

In followup to the event, a crlwatch project has been announced within a corresponding lengthy writeup on the technical matters of the incident.

The crlwatch project itself will help monitor the revocation of certs in response to breaches like this one.

More data is being provided as I write this post. It will be updated as more details come in.

A Web of (Mis)Trust?

Your email address will not be published. Required fields are marked *

 

Reports

BlindEagle flying high in Latin America

Kaspersky shares insights into the activity and TTPs of the BlindEagle APT, which targets organizations and individuals in Colombia, Ecuador, Chile, Panama and other Latin American countries.

APT trends report Q2 2024

The report features the most significant developments relating to APT groups in Q2 2024, including the new backdoor in Linux utility XZ, a new RAT called SalmonQT, and hacktivist activity.

Subscribe to our weekly e-mails

The hottest research right in your inbox