ALL >> Computers >> View Article
Certification Authority Alerts Users On Fraudulent Ssl Certificates
Recently, Comodo Group, Inc., one of the leading certification authorities warned against nine fraudulent Secure Sockets Layer (SSL) certificates issued by a Registration Authority. The registration authority reportedly suffered a security breach incident, which led to the disclosure of a user account. The compromised user account was used by the attacker to create new authentication credentials, placing and receiving order for certifications. The fraudulent certificates affect login.live.com, mail.google.com, google.com, login.yahoo.com (3 fraudulent certificates), login.skype.com, addons.mozilla.org and global trustee.
Cybercriminals could use sophisticated techniques to lure users to visit websites using fraudulent certificates. As the sites appear legitimate to the users, they may enter the authentication details on the website, which could be extracted by the attackers. The fraudulent certificates could also be used to trick users to download files containing malware on their computer systems. The malware could be designed to extract confidential personal or business information. Attackers could use the fake certificates ...
... to spoof content or launch phishing attacks. Cyber education is crucial to combat growing security threats. Training sessions, seminars, online degree and e-learning programs could help in enlightening employees on Internet security issues and improve the IT security practices in organizations.
Computer forensics experts are investigating the case and the registration authority has been suspended pending investigation. The fraudulent certificates have been revoked. The certification authority has reported to the respective government authorities, browser vendors and domain owners regarding the issue of fraudulent SSL certificates.
Security breaches could be prevented by evaluating the IT infrastructure at frequent intervals through IT professionals qualified in penetration testing, security audit, masters of security science to identify and mitigate security flaws.
United States Computer Emergency Readiness Team (US-CERT) has also cautioned users against the fraudulent certificates Major browser vendors have updated their browsers to identify and block the fraudulent certificates. Mozilla has updated Firefox 3.5, 3.6 and 4.0 to block these certificates. Microsoft has released updates for Windows to address the issue. Internet users must install and regularly update anti-virus software in their computer systems. Regular adherence to security advisories and updates from developers would also help in preventing malicious attacks. Distance learning and online university degree programs could enable IT professionals to update their skill sets to combat the growing IT security threats. IT administrators must keep track of the software updates and patch releases to secure the organizational networks and computer systems from intrusions and unauthorized access.
Add Comment
Computers Articles
1. Exploring How Ai In The Cloud Can Transform Your BusinessAuthor: TechDogs
2. The Power Of Cloud And Ai: A New Era Of Collaboration
Author: TechDogs
3. Get Business Insights Using Expedia & Booking. Com Review Data Scraping
Author: DataZivot
4. Top 10 Reasons A Strong Communication Strategy Drives Prm Program Success
Author: Archi
5. Achieve Scalable Web Scraping With Aws Lambda
Author: Devil Brown
6. Overcoming Common Challenges In Iso 27001 Implementation
Author: Jenna Miller
7. Basic Computer Course: Your Gateway To Skill Development | The Institute Of Professional Accountants
Author: Tipa Institute
8. Top 7 Advantages Of React Js
Author: Bella Stone
9. Top 7 App Marketing Tools For Mobile Success
Author: Bella Stone
10. Revolutionizing Education Management With Samphire It Solution Pvt Ltd’s Erp Software
Author: CONTENT EDITOR FOR SAMPHIRE IT SOLUTIONS PVT LTD
11. Top 10 Healthcare Technology Trends
Author: goodcoders
12. "building Tomorrow’s Factories: The Role Of Automation & Robotics In Modern Manufacturing"
Author: andrew smith
13. The Ultimate Guide To The Best Ecommerce Plugin For Wordpress
Author: Rocket Press
14. Xsosys Erp: A Scalable Solution For Businesses In Any Industry
Author: Xsosys Technology(S) Pte. Ltd.
15. Rental Management Software: A Complete Solution For Car, Property, And Coworking Space
Author: RentAAA