PDA

View Full Version : SSL certs stolen, browsers add them to blacklist


PrntRhd
03-24-2011, 01:19 AM
http://www.h-online.com/security/news/item/SSL-meltdown-forces-browser-developers-to-update-1213358.html
the Comodo SSL Certification Authority may have been compromised. As a consequence, criminals apparently obtained nine certificates for web sites that already existed, including addons.mozilla.org. There is no official statement on whether the situation was caused by insufficient checks during the certification process or by a breach of Comodo's infrastructure.

Note the 3 new additions of Firefox have had the stolen cert serial numbers added to their blacklists.