Skip Links

Expert: Iran might be stealing passwords from citizens to tighten censorship

SSL certificates were stolen from vendor Comodo

By Tim Greene, Network World
March 24, 2011 09:38 AM ET
  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Iran's apparent theft of valid SSL certificates may be an attempt to trap Iranians who use the Internet to duck the government's restrictions, a security expert says.

Reaction: Microsoft secures IE from stolen certs

The certificates stolen from certificate vendor Comodo could be used to reroute users to servers that appear to be legitimate but are not, says Mikko Hypponen, chief researcher at F-Secure in the company's blog

The certificates in question were issued to mail.google.com, www.google.com, login.yaoo.com, login.skype.com, addons.mozilla.org and Global Trustee.

Hypponnen says the certs could be used to gather passwords. Since the government controls Internet routing in the country, it could reroute all Skype traffic to a fake Skype login page and collect user names and passwords with the SSL encryption seemingly in place. Monitors could read e-mail accounts as well that seem protected by SSL encryption because the certificates are valid, he says. "Even most geeks wouldn't notice this was going on," he says.

Comodo suspects involvement by the Iranian government because of how well directed the attack was and how quickly it was executed.

Hypponen cites fellow researcher Eric Chien at Symantec as speculating the addons.mozilla.org could be used to block installation of certain extensions to the Firefox browser that would bypass censorship filters, such as FoxyProxy that automatically switches Internet connections across multiple proxy servers. This could be used to anonymize traffic.

Read more about security in Network World's Security section.

  • Print

Videos

rssRss Feed