Iran General NewsGoogle users in Iran targeted in certificate scam

Google users in Iran targeted in certificate scam

-

AFP: A false Internet security certificate has been used in an apparent attempt to snoop on Google users in Iran, according to the Internet search giant and computer security firms.

By Chris Lefkow

WASHINGTON (AFP) — A false Internet security certificate has been used in an apparent attempt to snoop on Google users in Iran, according to the Internet search giant and computer security firms.

A Dutch company, DigiNotar, which issues the Internet security credentials known as SSL certificates, said on Tuesday that it had revoked the “fraudulent certificate” in question.

SSL certificates are used to verify to visitors that a particular website is authentic and are issued by DigiNotar and other firms known as Certification Authorities.

Internet users whose browsers are fooled by a false certificate could unwittingly reveal their activity to another party in what is known as a “man-in-the-middle attack.”

DigiNotar said it had suffered an “intrusion” into its Certificate Authority infrastructure on July 19 which resulted in the “fraudulent issuance of public key certificate requests for a number of domains, including Google.com.”

“At that time, an external security audit concluded that all fraudulently issued certificates were revoked,” DigiNotar said. “Recently, it was discovered that at least one fraudulent certificate had not been revoked at the time.

“After being notified by Dutch government organization Govcert, DigiNotar took immediate action and revoked the fraudulent certificate,” it said.

Google said in a blog post late on Monday that it had “received reports of attempted SSL man-in-the-middle attacks against Google users, whereby someone tried to get between them and encrypted Google services.

“The people affected were primarily located in Iran,” said Heather Adkins, an information security manager at Google.

“The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google,” she said.

Adkins said users of the Google Chrome Web browser were protected from the attack “because Chrome was able to detect the fraudulent certificate.”

“To help deter unwanted surveillance, we recommend that users, especially those in Iran, keep their Web browsers and operating systems up to date and pay attention to Web browser security warnings,” she added.

Microsoft, maker of the Internet Explorer Web browser, said it had removed the DigiNotar certificate from the “Microsoft Certificate Trust List.”

Mozilla, maker of the Firefox browser, said it was releasing new desktop and mobile versions of Firefox “that will revoke trust in the DigiNotar root and protect users from this attack.”

Computer security firm F-Secure said there was a similar incident in May that was “tied to Iran” and “it’s likely the Government of Iran is using these techniques to monitor local dissidents.”

F-Secure said an attacker using a false SSL certificate could potentially “impersonate Google — assuming you can first reroute Internet traffic for google.com to you.

“This is something that can be done by a government or by a rogue ISP (Internet Service Provider),” it said.

F-Secure also said the intent would not be to monitor traffic to search engine google.com.

“This is about the Gmail servers at mail.google.com and Google Docs at docs.google.com and maybe Google+ at plus.google.com,” it said.

Latest news

Iran’s Negative Economic Growth: From Statistical Manipulation to the Collapse of Investment

When the gap between official figures and reality becomes too wide, the economic crisis is no longer confined to...

Iraq Sets September 30 as Deadline for Disarmament of Iranian Regime-Backed Militia Groups

Iraqi government spokesperson Haider al-Aboudi announced on Monday, June 29, that the government has given Shiite armed groups backed...

Escalating Iran-US Conflict Cuts Strait of Hormuz Traffic, Lifts Oil Prices

Oil Prices Rise and Ship Traffic Through the Strait of Hormuz Declines Following Tensions Between Iran and the United...

The ‘No To Executions Tuesdays’ campaign has entered its 127th week

The campaign “No to Executions Tuesdays,” a prisoner-led protest against executions held across multiple prisons in Iran, entered its...

Sixty-two Members of the Iranian Regime’s Assembly of Experts Call for Keeping the Strait of Hormuz Closed

As signs of divisions and rivalry at the highest levels of the Iranian regime have become increasingly apparent, 62...

Workers and Retirees in Iran Once Again Protest Over Living Conditions

Retirees and workers held protest gatherings and marches in several cities across Iran on Sunday, June 28, once again...

Must read

17 Iranian Workers Injured in Fire Incident at Production Unit in Qom

By Jubin Katiraie Seventeen workers were injured after a...

Iran judicial branch chief fires back at president

AP: The head of Iran's judiciary lashed out at...

You might also likeRELATED
Recommended to you