Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

car insurance prices
Tracking System

Popular content

Last viewed:

  • Surveillance Editorial Roundup
  • Pseudonyms: The Natural State of Online Identity
  • DOJ Pushing to Expand Warrantless Access to Internet Records
  • Air Force Emails Sensitive Information to Tourism Site
  • NSA Domestic Surveillance Began 7 Months Before 9/11, Convicted Qwest CEO Claims
  • White House proposal would ease FBI access to records of Internet activity
  • Spooks Get Their Own MySpace

tags in Topics

Activists Alert Anonymity Companies Copyright Court (US) Databases Data Mining DMCA Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

EFF to Verizon: Etisalat Certificate Authority Threatens Web Security

Submitted by MacRonin on August 13, 2010 - 11:05pm
  • Activists
  • Alert
  • Companies
  • Company Technology
  • Cryptography
  • Editorial
  • EFF
  • Government
  • Hmmm
  • ID
  • Infrastructure
  • Privacy
  • Rights
  • Security
  • SSL
  • Verizon
  • Verizon
  • Violations

EFF to Verizon: Etisalat Certificate Authority Threatens Web Security: Via EFF.org Updates.

EFF will soon be launching the SSL Observatory project, an effort to monitor and secure the cryptographic infrastructure of the World Wide Web. There is much work to be done, and we will need the help of many parties to make the HTTPS-encrypted web genuinely trustworthy. To see why, you can read the following letter, which we are sending to Verizon today:

(there is also a story in the New York Times)

Dear Verizon,

We are writing to request that Verizon investigate the security and privacy implications of the SSL CA certificate (serial number 0x40003f1) that Cybertrust (now a division of Verizon) issued to Etisalat on the 19th of December, 2005, and evaluate whether this certificate should be revoked.

As you are aware, Etisalat is a telecommunications company headquartered in the United Arab Emirates. In July 2009, Etisalat issued a mislabeled firmware update to approximately 100,000 of its BlackBerry subscribers that contained malicious surveillance software [1]. Research In Motion subsequently issued patches to remove this malicious code [2].

More recently, the United Arab Emirates Telecommunications Regulatory Authority and Etisalat threatened to discontinue service to BlackBerry users, claiming that these devices "allow users to act without any legal accountability, causing judicial, social and national security concerns for the UAE", apparently on account of Research In Motion's refusal to offer surveillance back doors in its encryption services [3].

These events clearly demonstrate that Etisalat and the UAE regulatory environment within which it operates are institutionally hostile to the existence and use of secure cryptosystems. It is therefore of great concern to us that Etisalat is in possession of a trusted SSL CA certificate and the
accompanying private key, which effectively functions as a master key for the encrypted portion of the World Wide Web. Etisalat could use this key to issue itself valid HTTPS certificates for verizon.com, eff.org, google.com, microsoft.com, or indeed any other website. Etisalat could use those certificates to conduct virtually undetectable surveillance and attacks against those sites. Etisalat's keys could also possibly be used to obtain access to some corporate VPNs.

We believe this situation constitutes an unacceptable security risk to the Internet in general and especially to foreigners who use Etisalat's data services when they travel.

We do not know whether Etisalat is willing to use its SSL CA keys for surveillance; however, the malicious code that Etisalat distributed last year had been signed by cryptographic keys that gave it access to various security-sensitive parts of the Blackberry's API [4][5], indicating a willingness on Etisalat's part to use other keys for the wholesale subversion of security measures intended to protect users' privacy.

Because Microsoft, Mozilla, and other browser vendors have chosen to delegate certificate issuing authority to Verizon/Cybertrust, and because Cybertrust in turn chose to delegate this authority to Etisalat, Verizon is now the only party in a position to mitigate this risk to Internet security in a manner that is prompt and minimizes side-effects. We therefore request that Verizon reevalute whether Etisalat is a trustworthy Certificate Authority, and determine whether may be appropriate to issue a new CRL revoking Etisalat's CA certificate.

Read Original Article:(Via EFF.org Updates.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • The Secrecy Double-Standard
  • Fully-qualified Nonsense in the SSL Observatory
  • Appeals Court Strengthens Warrantless Searches at Border
  • Justice Dept. to Congress: Don’t Saddle 4th Amendment on Us
  • Feds, RIAA Ask $22,500 in Damages Per Song
  • Building a better Certificate Authority (CA) infrastructure
  • Where’s EFF? Why EFF Is Sometimes Quiet About Important Cases
  • Congressman Wants YouTube Video Covered Up
  • Man Creates "Creepy" Stalking App
  • Boston College Says Using WiFi Is a Sign of Infringement
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.