Skip to main content

Comodo attacker claims credit for DigiNotar breach

DigiNotar Google cert access map (FOX-IT)
Image used with permission by copyright holder

If unauthenticated postings on the Internet are to be believes—and we all know how that goes—the attacker who was behind a breach of the SSL affiliate registration authority Comodo earlier this year may be behind the recent compromise of Dutch SSL certificate authority DigiNotar. The attacker posted an announcement on Pastebin under the name “Comodohacker” claiming responsibility for the DigiNotar breach. In the message, the writer says the action was retaliation for the role of Dutch soldiers in Srebrenica in 1995, where more than 8,000 Muslims were killed by Serbian forces during the Bosnian War.

The same account was previously used earlier this year to describe the attack on SSL certificate authority Comodo. The attacker also claims to have infiltrated four more unnamed high-profile certificate authorities, and gained the ability to issue false certificates from them. He also claimed to have access to the widely-used certificate authority GlobalSign, and to have attempted an attack on StartCom.

“Comodohacker” has given interviews in the last year, and described himself as a 21 year-old Iranian student. Some security experts have also speculated that Comodohacker could be Turkish. However, the Iranian connection is interesting, especially since name of the IP addresses that used Google account information under the fraudulent Google certificate issued by DigiNotar were located in Iran.

In all, over 500 fraudulent certificates were issued from DigiNotar after its systems were compromised. DigiNotar’s auditor FOX-IT has found (PDF) that more than 300,000 unique IP addresses accessed Google accounts alone under the bogus certificate issued for Google. Supposedly-secure information on any of those sessions could, in theory, have been intercepted by a third party.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Why Llama 3 is changing everything in the world of AI
Meta AI on mobile and desktop web interface.

In the world of AI, you've no doubt heard about what OpenAI and Google have been up to. And now, Meta's Llama LLM (large language model) is becoming an increasingly important player in the game, especially with its open-source nature. Meta recently made a big splash with the launch of its Llama 3 AI model, and it's shaken up the field dramatically.

The reasons why are multiple and varied. It's free to use, it has a wide user base, and yes, it's open source, to name but a few. Here's why Llama 3 is taking the AI industry by storm and may shape its future for some time to come.
Llama 3 is really good
We can debate until the cows come home about how useful AIs like ChatGPT and Llama 3 are in the real world -- they're not bad at teaching you board game rules -- but the few benchmarks we have for how capable these AI are give Llama 3 a distinct advantage.

Read more
How to delete messages on your Mac
A MacBook and iPhone in shadow on a surface.

Apple likes to make things easy for its iPhone, iPad, and macOS devotees. When signed in with the same Apple ID on more than one of these devices, you’ll be able to sync your messages from one Apple product to the next. This means when you get a text on your iPhone, you’ll be able to pull it up through the Messages app on your Mac desktop.

Read more
The best laptop brands for 2024
best laptop brands hp spectre x360 13  2021 1

If you like to write, browse, game, or work in different parts of your home or office, one of the best laptops is a necessity in 2024. There are many to choose from, but you can first narrow your options by looking at laptops from the most established and respected brands.

Here's a list of the best laptop brands in 2024 to get you started.
Dell

Read more