Hacked Dutch CA Threatens Iranian Dissidents

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 4:27 am

A Dutch Certificate Authority, DigiNotar, has been taken over by the Dutch government due to lack of confidence in their security. Since they provide SSL certificates for banks and other sensitive transactions, this is a real major problem. The goal appears to have been to compromise the Gmail accounts of dissidents in Iran.

Hackers broke in and used DigiNotar's root certificate to issue certificates for sites including Gmail and Google, MI6, the CIA, Facebook, Microsoft, and Skype and Twitter. The number of issued certificates was originally reported at around 250, but this has suddenly doubled in the last couple days, probably leading to the government takeover.

To give an idea of how serious this can be, Verisign keeps their root CA certificates on computers inside a complex with barbed wire, patrolling attack dogs, and guards with automatic weapons. These measures are required by their insurance company; without them, the insurers will not provide them with liability insurance. The site is not connected to the Internet; certificates generated from the root CA certificates are carried out on removable media after generation.

The Gmail certificate(s) could be used to perpetrate an attack in which the user compromises their password, by allowing an attacker to spoof the victim's browser into believing the user is connected to Gmail, after which they enter their username and password, are denied, and are re-forwarded to Gmail to prevent them realizing they've been compromised. Attackers, presumably members of the security service in Iran, could later log in to their accounts and read their email, possibly finding evidence that could be used to persecute them.

The certificates have been revoked, but it was not clear to me from reading the article whether that was all of them, or only the first 250-some-odd. Revocation will cause browsers to bring up warnings, but only after the revocation has propagated, which is an autonomous process that is not under user control.

Read all about it.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 5:25 am

Next bit: Looks like they got 300,000 Iranians to try to log in using the fake certificates:

http://www.pcworld.com/businesscenter/a ... mised.html

I'm guessing next comes the purge. So much for how "enlightened" the Iranians are, and how "evil" the US is for opposing the mullahs. How many people do you suppose they're going to torture to death this year?
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Gawd
Posts: 2140
Joined: Wed Feb 24, 2010 7:03 pm
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Gawd » Tue Sep 06, 2011 5:34 am

Schneibster wrote:Next bit: Looks like they got 300,000 Iranians to try to log in using the fake certificates:

http://www.pcworld.com/businesscenter/a ... mised.html

I'm guessing next comes the purge. So much for how "enlightened" the Iranians are, and how "evil" the US is for opposing the mullahs. How many people do you suppose they're going to torture to death this year?
Fewer than the Americans. It's true.

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 5:50 am

The UN disagrees with you and the General Assembly of the UN approved a resolution expressing deep concern at the ongoing human rights violations in Iran in December of 2010.

There don't appear to be any UN resolutions expressing concern about human rights violations by the US. Perhaps you'd care to explain why.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Gawd
Posts: 2140
Joined: Wed Feb 24, 2010 7:03 pm
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Gawd » Tue Sep 06, 2011 6:04 am

Schneibster wrote:The UN disagrees with you and the General Assembly of the UN approved a resolution expressing deep concern at the ongoing human rights violations in Iran in December of 2010.

There don't appear to be any UN resolutions expressing concern about human rights violations by the US. Perhaps you'd care to explain why.
Ever heard of who is on the UN Security Council that can veto anything they want?

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 6:06 am

This is the General Assembly.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Gawd
Posts: 2140
Joined: Wed Feb 24, 2010 7:03 pm
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Gawd » Tue Sep 06, 2011 6:08 am

Schneibster wrote:This is the General Assembly.
And the General Assembly voted to condemn Israel and guess who vetoed it?

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 6:10 am

And that changes the fact that Iran is engaged in massive human rights abuses because...?

Don't change the subject.

ETA: You and I both know perfectly well who did that hack, and why. I guess they had to do something with all those SAVAK guys, right?

Remember Neda.
Last edited by Schneibster on Tue Sep 06, 2011 6:12 am, edited 1 time in total.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Gawd
Posts: 2140
Joined: Wed Feb 24, 2010 7:03 pm
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Gawd » Tue Sep 06, 2011 6:12 am

Schneibster wrote:And that changes the fact that Iran is engaged in massive human rights abuses because...?

Don't change the subject.
Well, if you don't make Israel follow it, Iran doesn't have to.

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 6:13 am

Remember Neda.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Robert_S
Cookie Monster
Posts: 13416
Joined: Tue Feb 23, 2010 5:47 am
About me: Too young to die of boredom, too old to grow up.
Location: Illinois
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Robert_S » Tue Sep 06, 2011 6:26 am

Gawd wrote:
Schneibster wrote:And that changes the fact that Iran is engaged in massive human rights abuses because...?

Don't change the subject.
Well, if you don't make Israel follow it, Iran doesn't have to.
Lawd forbid anyone condemn anything until Israel has her shit perfect.
What I've found with a few discussions I've had lately is this self-satisfaction that people express with their proffessed open mindedness. In realty it ammounts to wilful ignorance and intellectual cowardice as they are choosing to not form any sort of opinion on a particular topic. Basically "I don't know and I'm not going to look at any evidence because I'm quite happy on this fence."
-Mr P

The Net is best considered analogous to communication with disincarnate intelligences. As any neophyte would tell you. Do not invoke that which you have no facility to banish.
Audley Strange

User avatar
Gawd
Posts: 2140
Joined: Wed Feb 24, 2010 7:03 pm
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Gawd » Tue Sep 06, 2011 6:27 am

Robert_S wrote:
Gawd wrote:
Schneibster wrote:And that changes the fact that Iran is engaged in massive human rights abuses because...?

Don't change the subject.
Well, if you don't make Israel follow it, Iran doesn't have to.
Lawd forbid anyone condemn anything until Israel has her shit perfect.
Israel never gets sanctioned. Fact.

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 6:31 am

This thread is not about Israel. It is about human rights violations in Iran, and about Iranian government hacking to try to catch dissidents so they can torture them.

Remember Neda.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Schneibster
Asker of inconvenient questions
Posts: 3976
Joined: Fri Sep 02, 2011 9:22 pm
About me: I hate cranks.
Location: Late. I'm always late.
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Schneibster » Tue Sep 06, 2011 6:35 am

Do feel free to start a thread about Israel and the Israeli/Palestinian conflict; you will find I am critical of both Israel and the Palestinians. But this is not that thread. Here we're talking about human rights violations in Iran, and about the Iranians apparently hacking a Dutch CA in order to catch more dissidents so they can torture them.
Everyone is entitled to his own opinion, but not his own facts. -Daniel Patrick Moynihan
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -Thomas Jefferson
Image

User avatar
Gawd
Posts: 2140
Joined: Wed Feb 24, 2010 7:03 pm
Contact:

Re: Hacked Dutch CA Threatens Iranian Dissidents

Post by Gawd » Tue Sep 06, 2011 6:38 am

Schneibster wrote:Do feel free to start a thread about Israel and the Israeli/Palestinian conflict; you will find I am critical of both Israel and the Palestinians. But this is not that thread. Here we're talking about human rights violations in Iran, and about the Iranians apparently hacking a Dutch CA in order to catch more dissidents so they can torture them.
No need, I have my own forum for that stuff.

Post Reply

Who is online

Users browsing this forum: No registered users and 26 guests