Showing posts with label MCS. Show all posts
Showing posts with label MCS. Show all posts

Thursday, 2 April 2015

Google Says Trust Certificates In Chinese CNNIC CA


Due to a recent incident with wrongly issued SSL certificates for Google sites Google has confidence in the Chinese certificate authority (CA) CNNIC terminated, which Google products such as Chrome will no longer recognize the certificates of CNNIC. Something that will be implemented through a future update for Chrome. Since this is very big impact, particularly Chinese Chrome users will have Google has decided to permit temporarily issued SSL certificates under CNNIC even by placing them on a public whitelist.

The reason for the measure is the recent discovery of rogue SSL certificates for various Google domains that were created by the Egyptian company MCS Holding. The company had been given the opportunity of CNNIC, which is a root CA. As root CA is CNNIC trusted by all major browsers. CNNIC had spent an intermediate certificate for MCS Holding, which the company for arbitrary domains could create SSL certificates. Because the intermediate certificate of CNNIC came, they were created SSL certificates also trusted by browsers.

According MCS Holding made ​​a human error sure that the existence of the rogue Google certificate was discovered. Google, Microsoft and Mozilla therefore decided to block these certificates. In addition, the CNNIC was heavily charged that MCS Holding gave an intermedia certificate, which the Chinese company had violated all sorts of rules. After further investigation, Google has now decided to tell all the confidence in CNNIC.
Certificate Transparency

Google argues in a statement that it believes that no other unauthorized SSL certificates have been issued or that the rogue Google certificates are used outside the test environment of MCS Holding. Regarding the Chinese certificate authority that Google must "Certificate Transparency" before implementing any request about the renewed confidence of CNNIC is considered.

Certificate Transparency is a technology developed by Google and is intended to address several structural flaws in the SSL certificate system. Thereby to unjustifiably spent and rogue SSL certificates are detected earlier. Mozilla has also decided to Certificate Transparency support .
Update

CNNIC called Google's decision unacceptable and unwise. The Chinese CA Google also calls to take the interests and rights of users into consideration. CNNIC let customers know their rights and interests will not be compromised.

Sunday, 29 March 2015

China Censor Messages On Google And Mozilla CNNIC


The Chinese authorities have messages from Google and Mozilla censored stating that Chinese certificate authority (CA) CNNIC has been involved in the issue of rogue Google certificate. Reported GreatFire.org , an organization that monitors censorship in China.

The rogue Google certificate which Google, Microsoft and Mozilla this week sounded the alarm had been created by the Egyptian company MCS Holding. The company had been given the opportunity of CNNIC, which is a root CA. As root CA is CNNIC trusted by all major browsers. CNNIC had spent an intermediate certificate for MCS Holding, which the company for arbitrary domains could create SSL certificates. Because the intermediate certificate of CNNIC came, they were created SSL certificates also trusted by browsers.

Both Mozilla and Google warned of rogue certificates and announced measures to protect their users. A famous Chinese IT blogger translated the message from Google that both Google and the Chinese search engine Baidu was well indexed. Not much later, the blogger via Twitter announced that he had received a call from the government that he had to remove his post immediately, which he did. The article Mozilla was acquired by several Chinese sites, including the state-owned Huanqiu.

Eventually, all these articles deleted. "This shows again the role CNNIC in the censorship apparatus. CNNIC was, is and will continue to internet censorship," said Great Fire. The organization calls Google, Mozilla, Microsoft and Apple also to say and draw the root certificate from the organization's confidence in CNNIC to protect users worldwide.

Friday, 27 March 2015

Egyptian Company: Google Rogue Certificates Were Mistake


The Egyptian company that had generated rogue SSL certificates for different websites from Google calls it a mistake that Google eventually discovered the certificates and hit alarm . Indeed, it was not intended that the certificates were discovered. This week, Google warned Internet users to rogue Google certificates generated by the Egyptian MCS Holding. Through the certificates could allow an attacker to Man-in-the-middle and phishing attacks on Internet users to intercept passwords and the contents of encrypted traffic.

MCS Holding is an Egyptian security company that delivers business networking. However, it had become a so-called "intermediate" certificate authority (CA), which was linked to the Chinese certificate authority CNNIC. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. In particular, Mozilla had great criticism of CNNIC that MCS Holding had given permission to the intermediate CA to generate SSL certificates.

The Egyptian company said in a statement that it had signed an agreement with CNNIC to a two-week period intermediate CA to act. This would be necessary for the testing of a new roll from cloud service. The test took place in a secure lab where the private key of the CA certifcate, to generate SSL certificates, stored in a firewall.

However, the firewall was set to automatically generate certificates for websites that were visited on the Internet. During an unguarded moment at the weekend would be one of the IT engineers decided to use the internet with Google Chrome. Chrome offers certificate pinning, which websites can indicate what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist.

Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. After MCS Holding by CNNIC had informed the certificate was immediately removed from the firewall and warned all parties involved. According to the Egyptian company, it is a human error which inadvertently took place. "We have no evidence of abuse, and we therefore recommend that people will not change their password or other action," said a company spokesman.

Measures

Meanwhile, Google has revoked the intermediate certificate of MCS Holding and also a Microsoft update released under Windows Users. From the description of the software giant appears that certificates for domains *. google.com , *.google.com.eg , *. g.doubleclick.net , *. gstatic.com , www.google.com , www.gmail .com and *. googleapis.com were created. Firefox comes next week with an update to revoke the certificate.

On the mailing list of Mozilla developers after the incident a heated debate erupted or CNNIC is not guilty because it would have violated all sorts of rules. While some want CNNIC is removed from the root store of Firefox. Mozilla could do this then this can have very serious consequences, especially for Chinese Firefox users, thereby HTTPS sites with SSL certificates of CNNIC and suspended beneath intermediate CAs can not visit. The Chinese CA Mozilla has therefore asked not to remove it from the root store CNNIC.

Tuesday, 24 March 2015

Google Sounds Alarm On Rogue Google certificate



Google warns Internet users to rogue Google certificate issued by a company from the United Arab Emirates and could be used to perform man-in-the-middle and phishing attacks on Internet users, so as passwords and the contents of encrypted traffic intercept. SSL certificates are used inter alia for encrypting traffic between websites and visitors and identifying websites.

The company that rogue SSL certificates issued is MCS Holdings , a so-called "intermediate" certificate authority (CA), which is linked to the Chinese CNNIC certificate authority. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. CNNIC is in all major "root certificate stores" so the Google unfairly issued certificates would be trusted by most browsers and operating systems.

Chrome on Windows, OS X and Linux, ChromeOS and Firefox 33 and newer would have refused the certificate because certificate-pinning. According to Google, there are probably also issued certificates for other websites that may not be recognized by certificate-pinning. Certificate-pinning sites may indicate by what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist. Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. Browsers like Chrome and Firefox currently support only pinning for some great websites.

Proxy

Following the fraudulent certificates, which were discovered on 20 March, Google CNNIC approached and was told that MCS Holdings only if issued certificates for domains they had registered themselves. That turned the company does not have done. MCS Holdings provides proxy appliances and firewall solutions that enable organizations of workers through the encrypted traffic can intercept self signed certificates. Should normally be set to the office computers to trust the proxy, but in this case it was not required by the wrongly issued certificates.

Google sees similarities with previously unduly certificates issued in 2013 by the French CA ANSSI . The Internet giant also denounces that CNNIC the power to create SSL certificates awarded to a company that was not suitable here. Chrome users do not have to do to be protected from rogue certificates, while Firefox users will have to wait for the arrival of Firefox 37 in which the certificate has been revoked. This version on March 31 appear.