{"id":2851,"date":"2012-03-20T07:00:45","date_gmt":"2012-03-20T15:00:45","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=2851"},"modified":"2012-03-20T07:00:45","modified_gmt":"2012-03-20T15:00:45","slug":"digital-certificates-compromised-keys-threaten-a-foundation-of-security","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/digital-certificates-compromised-keys-threaten-a-foundation-of-security\/","title":{"rendered":"Digital Certificates: Compromised Keys Threaten a Foundation of Security"},"content":{"rendered":"<p>SSL certificates encrypt and secure data. \u00a0The SSL certificate was designed to bring security to the internet<\/p>\n<p>A <a title=\"Digital Certificate defined on Wikipedia\" href=\"http:\/\/en.wikipedia.org\/wiki\/Public_key_certificate\" target=\"_blank\">digital certificate<\/a> is an electronic document that uses a digital signature to\u00a0bind a public key to an identify. \u00a0The certificate verifies that the individual or organization is the owner of the public key. \u00a0The information encrypted into the certificate \u00a0typically includes information like the name of the person or organization, address, and unique certificate serial number. \u00a0Digital certificates are used to validate ownership to enable secure data transfer.<\/p>\n<p>While the process to create and use an SSL certificate isn&#8217;t rocket science, it isn&#8217;t necessary trivial or hassle-free either. \u00a0<a title=\"Roger Grimes bio\" href=\"http:\/\/www.infoworld.com\/blogs\/roger-grimes\" target=\"_blank\">Roger Grimes<\/a>, contributor at InfoWorld and Principle Security Architect at Microsoft, <a title=\"BlackHat on SSL misconfigurations\" href=\"http:\/\/www.infoworld.com\/d\/security\/chrome-turns-its-back-security-standard-186362\" target=\"_blank\">reports from a BlackHat conference<\/a> that it&#8217;s estimated \u00a0that 90 percent of SSL digital certificates are misconfigured. \u00a0A <a title=\"Venafi research survey on SSL certificate management\" href=\"http:\/\/www.venafi.com\/new-research-reveals-poor-insight-into-ssl\/\" target=\"_blank\">survey <\/a>conducted by Venafi and Osterman Research found that 54 percent of organixations admit to being lax in their management of SSL certificates. \u00a044 percent of companies manage the lifecycle of their SSL digital certificates with post-it notes and spreadsheets.<\/p>\n<p><a title=\"Jeff Hudson bio\" href=\"http:\/\/www.linkedin.com\/pub\/jeff-hudson\/1\/413\/9aa\" target=\"_blank\">Jeff Hudson<\/a>, CEO of Venafi, said that &#8220;Organizations protect mission-critical and often regulated data with hundreds or thousands of encryption keys and digital certificates. \u00a0But as this survey reveals, too many companies have inaccurate or incomplete data about their security assets. The unquantified and unmanaged risks these certificates and keys pose is significant\u2014risks magnified through the increasingly pervasive use in corporate data centers, cloud-based systems and mobile devices.&#8221;<\/p>\n<p>But despite these problems, the real problem with SSL certificates isn&#8217;t on the web-site implementation side. \u00a0The problem is with the companies that create and issue SSL certificates. \u00a0Security Breaches at Certificate Authorities (CA) like Verisign, <a title=\"Diginotar attack\" href=\"https:\/\/www.eff.org\/deeplinks\/2011\/09\/post-mortem-iranian-diginotar-attack\" target=\"_blank\">Diginotar <\/a>and <a title=\"Comodo SSL breach\" href=\"http:\/\/blogs.comodo.com\/it-security\/data-security\/the-recent-ra-compromise\/?key5sk1=8975b4775a3de18f99e0836543bb19e50ca3c394&amp;key5sk2&amp;key5sk3=1330335780000&amp;key5sk4&amp;key5sk5=1330335799000&amp;key6sk1&amp;key6sk2=CH180102539&amp;key6sk3=5&amp;key6sk4=en-us&amp;key6sk5=US&amp;key6sk6=0&amp;key6sk7=http:\/\/blogs.comodo.com\/category\/it-security\/&amp;key6sk8=111102&amp;key6sk9=19201080&amp;key6sk10=true&amp;key6sk11=cf74bb4030f9c644d049df4ff76c293150656838&amp;key7sk1=0000&amp;key7sk2=0000\" target=\"_blank\">Comodo<\/a> have made headline news over the last months. \u00a0Experts expect that other CA&#8217;s have also been compromised but have not gone public with the information.<\/p>\n<p>The biggest and most recent reporting has been with Verisign. \u00a0In February 2011, Verisign admitted that their servers had been hacked in 2010. \u00a0Their October 2011 <a title=\"Verisign filing with the SEC\" href=\"https:\/\/investor.verisign.com\/secfiling.cfm?filingID=1193125-11-285850&amp;CIK=1014473\" target=\"_blank\">filing with the SEC<\/a> stated that &#8220;In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers.&#8221; \u00a0With more than 110 million domains registered with Verisign, a potential breach of their system could result in devastating loss or disruption.<\/p>\n<p>What&#8217;s the alternative to SSL? \u00a0Right now there isn&#8217;t really another option.<\/p>\n<p><a title=\"Jacob Appelbaum\" href=\"http:\/\/en.wikipedia.org\/wiki\/Jacob_Appelbaum\" target=\"_blank\">Jacob Appelbaum<\/a>, independent security researcher, <a title=\"Jacob Appelbaum on Digital Certificates\" href=\"https:\/\/blog.torproject.org\/blog\/diginotar-debacle-and-what-you-should-do-about-it\" target=\"_blank\">said<\/a> that &#8220;The Certificate Authority system as it stands today is a house of cards and we&#8217;re witnessing in public what many have known for years in private. The entire system is soaked in petrol and waiting for a light.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fdigital-certificates-compromised-keys-threaten-a-foundation-of-security%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>SSL certificates encrypt and secure data. \u00a0The SSL certificate was designed to bring security to the internet A digital certificate is an electronic document that uses a digital signature to\u00a0bind a public key to an identify. \u00a0The certificate verifies that<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/digital-certificates-compromised-keys-threaten-a-foundation-of-security\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31,36],"tags":[],"class_list":["post-2851","post","type-post","status-publish","format-standard","hentry","category-security","category-technology"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=2851"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2851\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=2851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=2851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=2851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}