China solar cell makers seek Taiwan partnershipshttp://bit.ly/JErUGz via @zdnetasia #solar #energy #china
13 minutes ago by newellpr on twitterZDNet is available in the following editions:
The Comodo security breach shows that each major browser maker ships a different list of master keys to Web authentication and that each creates its list in a different way.
technology, opera software asa, internet, internet browsers, science and technology, tunisia, microsoft corporation, venezuela, websites, computer technology
For all the tens of billions of dollars a year spent on Internet security a year, on everything from antivirus software to intrusion prevention, there's one component that's vital but remains obscure: which Web sites browsers decide to trust.
Each of the major browser makers has compiled a different list of who possesses the master keys to Web authentication--namely, who can be trusted to issue the secure digital certificates to create encrypted channels--and each has different procedures for approval. A closed lock icon typically appears in a browser and an "https://" connection is displayed when a Web site is deemed legitimate.
Today's system gives browser makers tremendous responsibility. Any list of so-called certificate authorities they include will be trusted by billions of Web browsers around the world, unless users take the time to change the settings. The surprise is, perhaps, that the lists of who's trusted aren't the same.
"Microsoft appears to generally trust a much larger set of certificate authorities than Mozilla does," says Peter Eckersley, senior staff technologist at the Electronic Frontier Foundation. "That may be because Microsoft's criteria are easier to meet in practice, or because certificate authorities prioritize getting onto Microsoft's list first."
Mozilla ships Firefox with a list of about 150 trusted certificate authorities. The list included with Microsoft Windows, used by Internet Explorer, totals 321 as of last week.
Opera includes only 37. Apple's OS X operating system, which Safari relies on, trusts 79 certificate authorities. Google says Chrome uses the Windows or OS X lists; Google Checkout trusts 168.
It's difficult to compare those numbers directly, though, because some certificate authorities are counted multiple times. VeriSign appears 55 times in Microsoft's list based on different types of products offered but only once in Opera's, for instance.
Microsoft explicitly trusts more government-operated certificate authorities than any other browser maker. The list includes: Brazil, Hong Kong, India, Japan, Latvia, Lithuania, Serbia, Slovenia, the United States, Tunisia, Turkey, Uruguay, and Venezuela.
Another complicating factor is that some browsers download updated lists of "root" certificate authorities as needed.
Opera's default "list starts out with a limited number of frequently used certificates," says Yngve Pettersen, a senior developer at Opera Software in Oslo, Norway. "The remainder are downloaded as needed from certs.opera.com when the user actually visits a site issued from a root...We pre-ship some roots and also some intermediates, while others are downloaded dynamically."
What makes the list of trusted certificate authorities crucial is that each possesses the master keys to Web authentication. Companies like Etisalat, a wireless carrier in the United Arab Emirates that implanted spyware on customers' BlackBerry devices, can generate certificates that can be used to impersonate any secure Web site on the Internet. So do more than 100 German universities, the U.S. Department of Homeland Security, and random organizations like the Gemini Observatory, which operates a pair of 8.1-meter-diameter telescopes in Hawaii and Chile.
A fraudulent certificate would allow a network provider (or a government) to use what's known as a man-in-the-middle attack to impersonate the legitimate sites and grab passwords, read e-mail messages, and monitor any other activities on those Web sites, even if browsers show that the connections were securely protected with SSL encryption. And in the last few years, plenty of other techniques have emerged to trick computers into visiting fake Web sites even without control of the network.
Microsoft says it included the Tunisian government as a trusted certificate authority after it went through the normal application process.
"Microsoft requires that certificate authorities applying to the program provide standardized information," says Bruce Cowper, Microsoft's group manager for trustworthy computing. Tunisia applied in 2006, he said, and its certificate was distributed in February 2007. Venezuela applied in September 2010, and was approved a month later.
Cowper declined to provide information about how many companies, organizations, or governments have failed to pass muster, saying "Microsoft does not share specific information about denied applications, but we do reject applications from certificate authorities who don't meet our criteria (or) fall into one of the named exclusions from the program." Microsoft's specifications say that any certificate authority that fails an audit, for instance, will be given the boot.
If a certificate authority "isn't in our list it is either because they have not asked to be included, or have not yet been approved," says Opera's Pettersen. "So far, I don't think we have refused any certificate authorities that have applied." Neither Tunisia nor Venezuela have sent Opera an application to be included, he said.
Neither Apple nor Comodo responded to requests for comment.
While both Microsoft and Opera make their criteria public, Mozilla goes further and even makes the list of pending applications public. Those include a certificate authority operated government of the Valencia region of Spain and Deutscher Sparkassen Verlag GmbH, the world's largest smartcard provider.
As a result of the Comodo breach (Comodo is currently trusted by all the major browsers), there's been talk among Mozilla developers of imposing what amounts to the Internet death penalty: revoking the company's certificate authority, at least until a security audit is performed, from the default Firefox configuration.
Lending ammunition to critics is that this is not the first time that Comodo has experienced a serious security breach. In 2008, a reseller issued an improperly acquired certificate for Mozilla.org.
And Comodo's chief technology officer, Robin Alden, wrote in February 2010 that, before issuing a certificate, "Comodo performs an automated check of domain control by sending (and confirming receipt of) an email to an address which is either on the domain to be validated or is explicitly mentioned in the Whois entry."
That apparently wasn't done when a Comodo business partner issued those fraudulent certificates earlier this month. Comodo declined to answer questions that ZDNet Asia's sister site CNET posed last week, including the identity of its reseller, what current audits were performed, and how much authority it delegates to partners.
Elinor Mills contributed to this report
China solar cell makers seek Taiwan partnershipshttp://bit.ly/JErUGz via @zdnetasia #solar #energy #china
13 minutes ago by newellpr on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/PUCv68Rd
1 hour ago by ALLsecuritySoft on twitterNews: Radio Costa Rica by EnjoyIT 1.0: Radio Costa Rica allows you to listen to a great var... http://t.co/BLzVT5As http://t.co/1Dhcy6ki
1 hour ago by CostaRica_VIP on twitterThe key for mobile operators is identifying the applications that are popular with subscribers on their network. They can then work partn...
2 hours ago by camcullen on Experience trumps content in apps monetizationExperience trumps content in apps monetization | ZDNet http://t.co/gBXcjbGd
3 hours ago by DennisOosterman on twitterExperience trumps content in apps monetization - ZDNet Asia News: "What we are doing currently is not to monetiz... http://t.co/S2EZtd8m
3 hours ago by kennyfabre1 on twitterMalaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said at the Sec... http://t.co/bgVlOBvx
5 hours ago by Bug2Hunt on twitter#security Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said ... http://t.co/hkFb4zrI
5 hours ago by Wiredsec on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/EEEmRM3j via @zdnetasia
5 hours ago by RedDragon1949 on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia News http://t.co/YpNMYgb5
5 hours ago by RedDragon1949 on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/FFems54Q
5 hours ago by mytech_pro on twitterChina solar cell makers seek Taiwan partnerships http://t.co/p5Hh7kJD
6 hours ago by Export2China on twitterBig data acquisitions pave way to fast, effective innovation http://t.co/hdiEfBsz via @zdnetasia
6 hours ago by jowoodley on twitterIntegration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 hours a... http://t.co/E7tsZbHJ
7 hours ago by Easyforexdotcom on twitterIntegration, focused investments to propel Windows Phone http://t.co/u9TqjQ8C
8 hours ago by ashvin_9 on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
5 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
6 days ago by wykoong on Drop the egos, copy ideas, then innovateThreats and malware know no boundaries. Neither should your web security. See how far Blue Coat Unified Web Security goes to protect your network.
Echelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.