123ArticleOnline Logo
Welcome to 123ArticleOnline.com!
ALL >> Computers >> View Article

Certification Authority Alerts Users On Fraudulent Ssl Certificates

Profile Picture
By Author: eccuni
Total Articles: 211
Comment this article
Facebook ShareTwitter ShareGoogle+ ShareTwitter Share

Recently, Comodo Group, Inc., one of the leading certification authorities warned against nine fraudulent Secure Sockets Layer (SSL) certificates issued by a Registration Authority. The registration authority reportedly suffered a security breach incident, which led to the disclosure of a user account. The compromised user account was used by the attacker to create new authentication credentials, placing and receiving order for certifications. The fraudulent certificates affect login.live.com, mail.google.com, google.com, login.yahoo.com (3 fraudulent certificates), login.skype.com, addons.mozilla.org and global trustee.

Cybercriminals could use sophisticated techniques to lure users to visit websites using fraudulent certificates. As the sites appear legitimate to the users, they may enter the authentication details on the website, which could be extracted by the attackers. The fraudulent certificates could also be used to trick users to download files containing malware on their computer systems. The malware could be designed to extract confidential personal or business information. Attackers could use the fake certificates ...
... to spoof content or launch phishing attacks. Cyber education is crucial to combat growing security threats. Training sessions, seminars, online degree and e-learning programs could help in enlightening employees on Internet security issues and improve the IT security practices in organizations.

Computer forensics experts are investigating the case and the registration authority has been suspended pending investigation. The fraudulent certificates have been revoked. The certification authority has reported to the respective government authorities, browser vendors and domain owners regarding the issue of fraudulent SSL certificates.

Security breaches could be prevented by evaluating the IT infrastructure at frequent intervals through IT professionals qualified in penetration testing, security audit, masters of security science to identify and mitigate security flaws.

United States Computer Emergency Readiness Team (US-CERT) has also cautioned users against the fraudulent certificates Major browser vendors have updated their browsers to identify and block the fraudulent certificates. Mozilla has updated Firefox 3.5, 3.6 and 4.0 to block these certificates. Microsoft has released updates for Windows to address the issue. Internet users must install and regularly update anti-virus software in their computer systems. Regular adherence to security advisories and updates from developers would also help in preventing malicious attacks. Distance learning and online university degree programs could enable IT professionals to update their skill sets to combat the growing IT security threats. IT administrators must keep track of the software updates and patch releases to secure the organizational networks and computer systems from intrusions and unauthorized access.

Total Views: 284Word Count: 401See All articles From Author

Add Comment

Computers Articles

1. Martindale Law Firm Competitive Analysis Data For Legal Industry
Author: Den Rediant

2. The Impact Of Digital Transformation In Clinical Trials
Author: Giselle Bates

3. Blending Art, Technology, And Access: A Look At Pure Art Sketch Community And Digital Portals
Author: new aurthors

4. Full Stack Development Company Driving Mvp Success Fast
Author: Rob Stephen

5. You May Need It Consulting Services But You Are Not Aware Of It Yet
Author: Helen Johns

6. Top Pos Dealers Solutions In 2025 | Best Pos Dealers In Hyderabad
Author: pbs

7. Newegg Product Data Scraping For E-commerce Market Intelligence
Author: Den Rediant

8. Coles & Woolworths Pricing Data Scraping For Retail Strategy
Author: Den Rediant

9. Answering_services
Author: brainbell10

10. Api_security
Author: brainbell10

11. Appium
Author: brainbell10

12. Out-of-stock Prediction Using Web Scraping For Inventory Management
Author: Den Rediant

13. Restaurant Data Scraping Api To Monitor Competitors In Real Time
Author: Den Rediant

14. Adobe_xd
Author: brainbell

15. Amazon Sagemaker Services
Author: brainbell10

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: