4 ms·
Do we actually know how many SSL certs Google uses, and for what? From what I can see: - Google Search & Google+ (https://encrypted.google.com/ https://encryp
by bwblabs 15y ago
Do we actually know how many SSL certs Google uses, and for what?
From what I can see:
- Google Search & Google+ (https://encrypted.google.com/ https://encrypted.google.com/ https://plus.google.com/ https://plus.google.com/) are using a *.google.com from GeoTrust/Google Internet Authority
- Google Mail (https://www.google.com/accounts/ https://www.google.com/accounts/) is using a www.google.com from VeriSign/Thawte
Ofcourse I'm also afraid that this is indeed a MITM attack against Iranian users.
With SSL certs that costs less than $15 you can expect that things cannot be thoroughly checked, however a Wildcard DigiNotar SSL cert is costing you € 750 a year (in a 4 year contract http://diginotar.nl/OnlinePrijsindicatie/tabid/1417/Default.aspx http://diginotar.nl/OnlinePrijsindicatie/tabid/1417/Default....), you would expect that these things would not be possible.
If they however hacked the root CA, it's even more scary, also Vasco (the mother company) makes virtually every Two-factor authentication used for Dutch Banking..
- blauwbilgorgel 15y agoScary indeed. Also responsible for authentication of DigiD, online taxes, pension funds, Chamber of Commerce, Ministry of Security and Justice, local governments, etc.
- joelhaasnoot 15y agoDidn't check it myself, but apparently DigiD for instance is on a different CA/root. DigiD is the Dutch "unified account" for all online government services: you can take out student loans, submit taxes, etc.
- blauwbilgorgel 15y agohttp://www.diginotar.nl/Aanvragen/Lopendeprojecten/DigiDMachtigen/tabid/2059/Default.aspx http://www.diginotar.nl/Aanvragen/Lopendeprojecten/DigiDMach... They have this listed as an active project, so they are definitely involved. Could still be on a different CA though. And of course _if_ they were hacked.