The most popular and comprehensive Open Source ECM platform
Digital Certificates: Compromised Keys Threaten a Foundation of Security
SSL certificates encrypt and secure data. The SSL certificate was designed to bring security to the internet
A digital certificate is an electronic document that uses a digital signature to bind a public key to an identify. The certificate verifies that the individual or organization is the owner of the public key. The information encrypted into the certificate typically includes information like the name of the person or organization, address, and unique certificate serial number. Digital certificates are used to validate ownership to enable secure data transfer.
While the process to create and use an SSL certificate isn’t rocket science, it isn’t necessary trivial or hassle-free either. Roger Grimes, contributor at InfoWorld and Principle Security Architect at Microsoft, reports from a BlackHat conference that it’s estimated that 90 percent of SSL digital certificates are misconfigured. A survey conducted by Venafi and Osterman Research found that 54 percent of organixations admit to being lax in their management of SSL certificates. 44 percent of companies manage the lifecycle of their SSL digital certificates with post-it notes and spreadsheets.
Jeff Hudson, CEO of Venafi, said that “Organizations protect mission-critical and often regulated data with hundreds or thousands of encryption keys and digital certificates. But as this survey reveals, too many companies have inaccurate or incomplete data about their security assets. The unquantified and unmanaged risks these certificates and keys pose is significant—risks magnified through the increasingly pervasive use in corporate data centers, cloud-based systems and mobile devices.”
But despite these problems, the real problem with SSL certificates isn’t on the web-site implementation side. The problem is with the companies that create and issue SSL certificates. Security Breaches at Certificate Authorities (CA) like Verisign, Diginotar and Comodo have made headline news over the last months. Experts expect that other CA’s have also been compromised but have not gone public with the information.
The biggest and most recent reporting has been with Verisign. In February 2011, Verisign admitted that their servers had been hacked in 2010. Their October 2011 filing with the SEC stated that “In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers.” With more than 110 million domains registered with Verisign, a potential breach of their system could result in devastating loss or disruption.
What’s the alternative to SSL? Right now there isn’t really another option.
Jacob Appelbaum, independent security researcher, said that “The Certificate Authority system as it stands today is a house of cards and we’re witnessing in public what many have known for years in private. The entire system is soaked in petrol and waiting for a light.”













