Skip to main content
  1. Home
  2. Computing
  3. Web
  4. Legacy Archives

Comodo attacker claims credit for DigiNotar breach

Add as a preferred source on Google
DigiNotar Google cert access map (FOX-IT)
Image used with permission by copyright holder

If unauthenticated postings on the Internet are to be believes—and we all know how that goes—the attacker who was behind a breach of the SSL affiliate registration authority Comodo earlier this year may be behind the recent compromise of Dutch SSL certificate authority DigiNotar. The attacker posted an announcement on Pastebin under the name “Comodohacker” claiming responsibility for the DigiNotar breach. In the message, the writer says the action was retaliation for the role of Dutch soldiers in Srebrenica in 1995, where more than 8,000 Muslims were killed by Serbian forces during the Bosnian War.

The same account was previously used earlier this year to describe the attack on SSL certificate authority Comodo. The attacker also claims to have infiltrated four more unnamed high-profile certificate authorities, and gained the ability to issue false certificates from them. He also claimed to have access to the widely-used certificate authority GlobalSign, and to have attempted an attack on StartCom.

Recommended Videos

“Comodohacker” has given interviews in the last year, and described himself as a 21 year-old Iranian student. Some security experts have also speculated that Comodohacker could be Turkish. However, the Iranian connection is interesting, especially since name of the IP addresses that used Google account information under the fraudulent Google certificate issued by DigiNotar were located in Iran.

In all, over 500 fraudulent certificates were issued from DigiNotar after its systems were compromised. DigiNotar’s auditor FOX-IT has found (PDF) that more than 300,000 unique IP addresses accessed Google accounts alone under the bogus certificate issued for Google. Supposedly-secure information on any of those sessions could, in theory, have been intercepted by a third party.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Gemini in Chrome can now see exactly what you’re looking at on screen
Google's new "Select from screen" tool makes it easier to ask Gemini questions about text and images in a browser tab.
Google Chrome Gemini Featured

Google is making Gemini a lot more aware of what's happening inside Chrome. The company has started rolling out a new "Select from screen" feature that lets users highlight specific text or images from a webpage and send them directly to Gemini, making conversations with the AI assistant far more contextual.

Gemini can now focus on exactly what users want to ask about

Read more
Microsoft’s new Surface PCs are cheaper — but there’s a catch
Cardboard, Box, Carton

The tech industry’s favorite balancing act is getting harder by the month. Component prices are rising, memory costs refuse to settle down, and laptop makers are scrambling to keep sticker shock under control. Microsoft’s latest Surface refresh feels like a direct response to that problem.

The company has introduced new entry-level versions of its 12-inch Surface Pro and 13-inch Surface laptop, offering lower starting prices without changing the processor or storage. On the surface, that sounds like good news for budget-conscious buyers. Dig a little deeper, however, and you’ll find a compromise hiding in plain sight.

Read more
A new supercomputer has dethroned the U.S — here’s why it matters
Crowd, Person, Architecture

The race to build the world’s fastest supercomputer has been dominated by the United States. Now, China has stormed back into the lead. A newly ranked system called LineShine has claimed the No. 1 position on the latest Top500 list, a closely watched ranking of the planet’s most powerful supercomputers. The machine, located in Shenzhen, pushed past the U.S. government’s El Capitan system and became the first Chinese computer to top the list since 2017. That’s notable on its own. But what makes LineShine particularly interesting is how it got there.

The tortoise just outran the rocket

Read more